Supply Chain 701 incidents

Software and hardware supply chain compromise incidents

Supply chain [SC]

Axios npm Supply Chain Compromise - Sapphire Sleet (DPRK) RAT Delivery

2026-03-31 [vendor] axios (npm HTTP client library) [malware] Sapphire Sleet RAT
Vector: Sapphire Sleet (North Korean state actor) compromised the npm publishing credentials for axios, one of the most popular JavaScript HTTP client libraries (~70 million weekly downloads), and published malicious versions 1.14.1 and 0.30.4 containing a backdoored dependency connecting to attacker C2

On March 31, 2026, Sapphire Sleet (a North Korean state-sponsored threat actor tracked by Microsoft) published two malicious versions of axios (1.14.1 and 0.30.4) to npm. Axios is …

Supply chain [SC]

TeamPCP Telnyx Python SDK PyPI Supply Chain Compromise

2026-03-27 [vendor] Telnyx Python SDK; PyPI [malware] TeamPCP Cloud Stealer
Vector: TeamPCP compromised Telnyx's PyPI publishing credentials (part of their cascading GitHub Actions credential theft campaign) and published two malicious versions of the Telnyx Python SDK to PyPI containing a three-stage RAT payload hidden inside WAV audio file frames

On March 27, 2026 at 03:51 UTC, TeamPCP published two unauthorized malicious versions of the Telnyx Python SDK (4.87.1 and 4.87.2) to PyPI. Both versions were quarantined by 10:13 …

Supply chain [SC]

TeamPCP Checkmarx KICS GitHub Actions Supply Chain Compromise

2026-03-21 [vendor] Checkmarx KICS (Keep Infrastructure as Code Secure); GitHub Actions [malware] TeamPCP Cloud Stealer
Vector: TeamPCP used GitHub Personal Access Tokens (PATs) stolen during the Trivy compromise to force-push malicious commits to all 35 version tags of the checkmarx/kics-github-action repository and poison version 2.3.28 of checkmarx/ast-github-action

On March 21, 2026, as the second step in its cascading supply chain campaign, TeamPCP used PATs stolen during the March 19 Trivy/Aqua Security GitHub Actions compromise to target …

Supply chain [SC]

GlassWorm Supply-Chain Attack - 72 Malicious Open VSX Extensions

2026-01-30 [vendor] Open VSX Registry (VS Code extension marketplace) [malware] GlassWorm
Vector: GlassWorm threat actor compromised a legitimate developer's Open VSX publishing credentials (leaked token or unauthorized access) to publish malicious extension versions; also abused extensionPack/extensionDependencies transitive dependency chains to turn benign extensions into GlassWorm delivery vehicles after trust was established

Since January 31, 2026, researchers identified at least 72 malicious Open VSX extensions linked to the GlassWorm campaign. On January 30, 2026, four established Open VSX extensions …

Supply chain [SC]

EHR Vendor Veradigm $10.5M Data Breach Lawsuit Settlement

2026-01-21
Vector: Veradigm (formerly Allscripts Healthcare Solutions) suffered a data breach affecting physician practice clients; the breach resulted in class-action litigation that settled for $10.5 million

Electronic health records vendor Veradigm (formerly Allscripts Healthcare Solutions, rebranded 2022) agreed to pay $10.5 million to settle a class-action lawsuit arising from a …

Supply chain [SC]

Tweet thread by TrustWallet

2025-12-25 [vendor] Trust Wallet [loss] $7M
Vector: Software supply chain attack

The Trust Wallet Chrome extension was compromised in an apparent supply chain attack. People who used the non-custodial wallet extension after it updated to version 2.68 lost funds …

Supply chain [SC]

Freedom Mobile Third-Party Breach (December 2025)

2025-12-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

In 2025, Freedom Mobile experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Third-party vendor. Source reporting: …

Supply chain [SC]

PornHub Third-Party Breach (December 2025)

2025-12-01 [vendor] Mixpanel
Vector: Compromise of third-party service provider / vendor relationship

In 2025, PornHub experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Mixpanel. Source reporting: …

Supply chain [SC]

Checkout.com Third-Party Breach (November 2025)

2025-11-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

In 2025, Checkout.com experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Third-party vendor. Source reporting: …

Supply chain [SC]

Logitech Third-Party Breach (November 2025)

2025-11-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

In 2025, Logitech experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Third-party vendor. Source reporting: …

Supply chain [SC]

Discord Third-Party Breach (October 2025)

2025-10-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

In 2025, Discord experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Third-party vendor. Source reporting: …

Supply chain [SC]

MANGO Third-Party Breach (October 2025)

2025-10-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

In 2025, MANGO experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Third-party vendor. Source reporting: …

Supply chain [SC]

Shai-Hulud Self-Replicating npm Supply Chain Worm (v1 + v2)

2025-09-14 [vendor] npm (Node Package Manager registry) [malware] Shai-Hulud
Vector: Novel self-replicating worm injected malicious post-install scripts into npm packages by compromising developer maintainer accounts; spread autonomously by stealing npm tokens and publishing backdoored versions of other packages maintained by the same developers

On September 14, 2025, the first malicious packages of the Shai-Hulud self-replicating worm appeared in the npm ecosystem. By September 16, over 180 packages were confirmed …

Supply chain

npm Supply Chain Attack: chalk, debug, and 16 Other Packages Compromised

2025-09-08 [vendor] npm registry [malware] Browser crypto wallet stealer (hooking window.ethereum, Solana APIs, fetch/XHR)
Vector: Phishing / adversary-in-the-middle attack against package maintainer 'qix' (Josh Junon): fake npm 2FA reset email (npmjs.help domain) captured username, password, and live TOTP code

On September 8, 2025, 18 widely used npm packages were compromised via an account takeover of maintainer 'qix'. Affected packages collectively receive 2.6+ billion downloads per …

Supply chain [SC]

BeyondTrust Third-Party Breach (September 2025)

2025-09-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

Salesforce / Drift Security Incident | BeyondTrust. BeyondTrust’s Privileged Access Management platform protects your organization from unwanted remote access, stolen …

Supply chain [SC]

BugCrowd Third-Party Breach (September 2025)

2025-09-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

Update: Bugcrowd Response to Salesloft Drift Third-Party Security Event | @Bugcrowd. We want to share an update to our blog post regarding the recent unauthorized access to …

Supply chain [SC]

Cato Networks Third-Party Breach (September 2025)

2025-09-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

In 2025, Cato Networks experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …

Supply chain [SC]

Chess.com Third-Party Breach (September 2025)

2025-09-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

In 2025, Chess.com experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Third-party vendor. Source reporting: …

Supply chain [SC]

ContentSquare Third-Party Breach (September 2025)

2025-09-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

In 2025, ContentSquare experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …

Supply chain [SC]

Dynatrace LLC. Third-Party Breach (September 2025)

2025-09-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

In 2025, Dynatrace LLC. experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …

Supply chain [SC]

Esker Third-Party Breach (September 2025)

2025-09-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

In 2025, Esker experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …

Supply chain [SC]

HackerOne Third-Party Breach (September 2025)

2025-09-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

In 2025, HackerOne experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …

Supply chain [SC]

Harrods Third-Party Breach (September 2025)

2025-09-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

In 2025, Harrods experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Third-party vendor. Source reporting: …

Supply chain [SC]

LiveRamp Third-Party Breach (September 2025)

2025-09-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

In 2025, LiveRamp experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …

Supply chain [SC]

Omada Third-Party Breach (September 2025)

2025-09-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

In 2025, Omada experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …

Supply chain [SC]

OneSpan Third-Party Breach (September 2025)

2025-09-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

In 2025, OneSpan experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …

Supply chain [SC]

Pantheon Third-Party Breach (September 2025)

2025-09-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

In 2025, Pantheon experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …

Supply chain [SC]

Proofpoint Third-Party Breach (September 2025)

2025-09-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

In 2025, Proofpoint experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …

Supply chain [SC]

Qualys, Inc. Third-Party Breach (September 2025)

2025-09-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

In 2025, Qualys, Inc. experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …

Supply chain [SC]

Sophos Ltd. Third-Party Breach (September 2025)

2025-09-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

In 2025, Sophos Ltd. experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …

Supply chain [SC]

SpyCloud, Inc. Third-Party Breach (September 2025)

2025-09-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

In 2025, SpyCloud, Inc. experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …

Supply chain [SC]

Stellantis Third-Party Breach (September 2025)

2025-09-01 [vendor] Salesforce
Vector: Compromise of third-party service provider / vendor relationship

In 2025, Stellantis experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Salesforce. Source reporting: …

Supply chain [SC]

Tenable, Inc. Third-Party Breach (September 2025)

2025-09-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

In 2025, Tenable, Inc. experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …

Supply chain [SC]

Wealthsimple Third-Party Breach (September 2025)

2025-09-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

In 2025, Wealthsimple experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Third-party vendor. Source reporting: …

Supply chain [SC]

Workiva Third-Party Breach (September 2025)

2025-09-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

In 2025, Workiva experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …

Supply chain [SC]

HIPAA Journal

2025-08-09 [vendor] Oracle E-Business Suite (Oracle Concurrent Processing) [cve] CVE-2025-61882 +1
Vector: CWE-306: Missing Authentication for Critical Function (CVE-2025-61882 Oracle EBS unauthenticated RCE, CVSS 9.8)

The Cl0p ransomware group exploited CVE-2025-61882, a critical CVSS 9.8 zero-day unauthenticated remote code execution vulnerability in Oracle E-Business Suite (EBS), beginning as …

Supply chain [SC]

JFrog Third-Party Breach (August 2025)

2025-08-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

JFrog Help Center. JFrog documentation has moved to a new and improved site at docs.jfrog.com. The Help Center will continue to serve as your dedicated hub for Support and FAQ …

Supply chain [SC]

Megaport Third-Party Breach (August 2025)

2025-08-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

Megaport Trust Center | Powered by SafeBase. See how Megaport manages their security program with SafeBase. Welcome to the Megaport Trust Center, where we demonstrate our …

Supply chain [SC]

Pi-hole Third-Party Breach (August 2025)

2025-08-01 [vendor] GiveWP WordPress
Vector: Compromise of third-party service provider / vendor relationship

Pi-hole discloses data breach triggered by WordPress plugin flaw. Pi-hole, a popular network-level ad-blocker, has disclosed that donor names and email addresses were exposed …

Supply chain [SC]

Rubrik Third-Party Breach (August 2025)

2025-08-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

Salesforce-Connected Third-Party Drift Application Supply Chain Incident Response. We use cookies to improve your experience, analyze traffic, and personalize content. Some are …

Supply chain [SC]

Tanium Third-Party Breach (August 2025)

2025-08-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

Salesloft Drift Data Breach: What We Know and What We're Doing. Hackers breached Salesloft in a major data theft campaign, stealing OAuth and refresh tokens linked to the Drift AI …

Supply chain [SC]

Zscaler Third-Party Breach (August 2025)

2025-08-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

Salesloft Drift Supply Chain Incident: Key Details and Zscaler’s. Zscaler swiftly mitigates a security incident impacting Salesloft Drift, and ensuring robust protection against …

Supply chain [SC]

Allianz Life Third-Party Breach (July 2025)

2025-07-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

Massive data breach confirmed by Allianz Life. U.S. life insurance firm Allianz Life had most of its 1.4 million customers' data compromised following a data breach this month, …

Supply chain [SC]

Louis Vuitton Third-Party Breach (July 2025)

2025-07-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

Louis Vuitton says regional data breaches tied to same cyberattack. Luxury fashion giant Louis Vuitton confirmed that breaches impacting customers in the UK, South Korea, and …

Supply chain [SC]

McDonald's Third-Party Breach (July 2025)

2025-07-01 [vendor] Paradox, Inc.
Vector: Compromise of third-party service provider / vendor relationship

'123456' password exposed chats for 64 million McDonald’s job chatbot applications. Cybersecurity researchers discovered a vulnerability in McHire, McDonald's chatbot job …

Supply chain [SC]

Coinbase Third-Party Breach (June 2025)

2025-06-01 [vendor] TaskUs
Vector: Compromise of third-party service provider / vendor relationship

Coinbase breach tied to bribed TaskUs support agents in India. A recently disclosed data breach at Coinbase has been linked to India-based customer support representatives from …

Supply chain [SC]

Glasgow City Council Third-Party Breach (June 2025)

2025-06-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

Glasgow City Council impacted by ‘cyber incident’. The Glasgow City Council announced that it was affected by an incident “disrupting a number of online services and which may have …

Supply chain [SC]

MainStreet Bank Third-Party Breach (June 2025)

2025-06-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

MainStreet Bank reports vendor cyber incident that leaked customer info. In regulatory filings with the Securities and Exchange Commission, MainStreet Bank's holding company said a …

Supply chain [SC]

Sharp Healthcare Third-Party Breach (June 2025)

2025-06-01 [vendor] Episource
Vector: Compromise of third-party service provider / vendor relationship

More than 5 million affected by data breach at healthcare tech firm Episource. California-based Episource disclosed in filings with the U.S. Department of Health and Human Services …

Supply chain [SC]

Switzerland Government Third-Party Breach (June 2025)

2025-06-01 [vendor] Radix (Zurich based and non-profit organization)
Vector: Compromise of third-party service provider / vendor relationship

Switzerland says government data stolen in ransomware attack. The government in Switzerland is informing that sensitive information from various federal offices has been impacted …

Supply chain [SC]

Adidas Third-Party Breach (May 2025)

2025-05-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

Adidas warns of data breach after customer service provider hack. German sportswear giant Adidas disclosed a data breach after attackers hacked a customer service provider and …

Supply chain [SC]

Catholic Health Third-Party Breach (May 2025)

2025-05-01 [vendor] Serviceaide
Vector: Compromise of third-party service provider / vendor relationship

Breaches at Serviceaide, Nationwide Recovery Services expose medical info of more than 500,000 people. Hospitals tied to the two companies announced breaches over the last week …

Supply chain [SC]

Marks & Spencer Third-Party Breach (May 2025)

2025-05-01 [vendor] Tata Consultancy Services (TCS)
Vector: Compromise of third-party service provider / vendor relationship

Marks & Spencer confirms customer data stolen in cyberattack. M&S said that some customer data — but not payment card details or passwords — had been breached in a recent …

Supply chain [SC]

TRG Medical Imaging Third-Party Breach (May 2025)

2025-05-01 [vendor] Nationwide Recovery Services (NRS)
Vector: Compromise of third-party service provider / vendor relationship

Nationwide Recovery Service Data Breach Victim List Grows: 560,000+ Individuals Affected. The list of victims from the data breach at the debt collection agency Nationwide Recovery …

Supply chain [SC]

Sharp HealthCare Episource Third-Party Breach

2025-05-01 [vendor] Episource (healthcare risk adjustment analytics)
Vector: Episource, a healthcare risk adjustment and analytics vendor, was breached, exposing patient records for Sharp HealthCare clients that had been shared with Episource for clinical documentation and risk adjustment analytics services

Sharp HealthCare, a major integrated regional health system in San Diego, California, disclosed in June 2025 that a breach at Episource, its third-party healthcare risk adjustment …

Supply chain [SC]

Ascension Third-Party Breach (April 2025)

2025-04-01 [vendor] Former business partner
Vector: Compromise of third-party service provider / vendor relationship

Ascension discloses new data breach after third-party hacking incident. ​Ascension, one of the largest private healthcare systems in the United States, is notifying patients that …

Supply chain [SC]

âRoyal Mail Third-Party Breach (April 2025)

2025-04-01 [vendor] Spectos GmbH
Vector: Compromise of third-party service provider / vendor relationship

In 2025, âRoyal Mail experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Spectos GmbH. Source reporting: …

Supply chain [SC]

Nationwide Recovery Services Healthcare Billing Vendor Breach (Multiple Hospitals)

2025-04-01 [vendor] Nationwide Recovery Services (medical billing/RCM)
Vector: Nationwide Recovery Services (NRS), a medical billing and revenue cycle management vendor, suffered a breach of its systems, exposing patient data from more than a dozen healthcare provider clients

In May 2025, Nationwide Recovery Services (NRS), a healthcare billing and accounts receivable management vendor, disclosed a data breach affecting over a dozen healthcare provider …

Supply chain [SC]

StreamElements Third-Party Breach (March 2025)

2025-03-01 [vendor] Gooten
Vector: Compromise of third-party service provider / vendor relationship

StreamElements Confirms Third-Party Data Breach from an Infostealer Infection. Stay informed with the latest insights in our Infostealers weekly report. Explore key findings, …

Supply chain [SC]

Bybit Cryptocurrency Exchange Hack via Safe{Wallet} Supply Chain

2025-02-21 [vendor] Safe{Wallet} (multi-sig wallet UI)
Vector: Social engineering against a Safe{Wallet} developer; AWS session token theft to compromise Safe{Wallet} infrastructure; malicious JavaScript injected into transaction signing UI

On February 21, 2025, Bybit (Dubai-based cryptocurrency exchange) suffered the largest cryptocurrency theft ever recorded: $1.46 billion in Ethereum stolen from a cold wallet. …

Supply chain [SC]

StreamElements Gooten Merchandise Operations Vendor Breach

2025-02-15 [vendor] Gooten (merchandise/print-on-demand fulfillment)
Vector: Gooten, a merchandise fulfillment and print-on-demand vendor used by StreamElements for its creator merchandise programs, was compromised, exposing StreamElements content creator customer data

StreamElements, a platform for live streaming tools and creator merchandise, disclosed in March 2025 that a third-party vendor breach had exposed customer data. The breach …

Supply chain [SC]

GrubHub Third-Party Breach (February 2025)

2025-02-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

GrubHub data breach impacts customers, drivers, and merchants. ​Food delivery company GrubHub disclosed a data breach impacting the personal information of an undisclosed number of …

Supply chain [SC]

94 K-12 Schools Third-Party Breach (January 2025)

2025-01-01 [vendor] PowerSchool
Vector: Compromise of third-party service provider / vendor relationship

PowerSchool hack exposes student, teacher data from K-12 districts. Education software giant PowerSchool has confirmed it suffered a cybersecurity incident that allowed a threat …

Supply chain [SC]

Khalil Foundation Third-Party Breach (January 2025)

2025-01-01 [vendor] Transform Studios
Vector: Compromise of third-party service provider / vendor relationship

Billing Support Vendor Notifies 701K Patients About December 2023 Data Breach. Medusind, a Florida-based revenue cycle management vendor and practice management software provider, …

Supply chain [SC]

Rostelecom Third-Party Breach (January 2025)

2025-01-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

Russian telecom giant Rostelecom investigates suspected cyberattack on contractor. Russia's Rostelecom said that it was responding to a cyberattack on a contractor that helps to …

Supply chain [SC]

Stiiizy Third-Party Breach (January 2025)

2025-01-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

380,000 Impacted by Data Breach at Cannabis Retailer Stiiizy. This website stores cookies on your computer. These cookies are used to improve your website experience and provide …

Supply chain [SC]

TalkTalk Third-Party Breach (January 2025)

2025-01-01 [vendor] CSG Ascendon
Vector: Compromise of third-party service provider / vendor relationship

TalkTalk investigates breach after data for sale on hacking forum. UK telecommunications company TalkTalk is investigating a third-party supplier data breach after a threat actor …

Supply chain [SC]

TalkTalk CSG Ascendon Telecom Platform Breach

2025-01-01 [vendor] CSG Ascendon (telecom billing/subscriber management SaaS)
Vector: Threat actors compromised CSG Ascendon, a third-party telecom billing and subscriber management platform used by TalkTalk, gaining access to subscriber account records

In January 2025, TalkTalk, the UK telecommunications provider, disclosed that a data breach had occurred via CSG Ascendon, its third-party subscriber management and billing …

Supply chain [SC]

Magento Extension Supply Chain Attack (Tigren, Meetanshi, MGS — 500-1000 E-Commerce Stores)

2025-01-01 [vendor] Tigren; Meetanshi; MGS (Magento extensions)
Vector: Attackers compromised the servers of three Magento extension vendors (Tigren, Meetanshi, and MGS/Mageplaza) and trojanized their extension packages to include a backdoor that exfiltrated customer payment card data and credentials from the e-commerce stores that installed them

In May 2025, security researchers disclosed that three Magento extension vendors — Tigren, Meetanshi, and MGS (Mageplaza) — had their extension distribution servers compromised. …

Supply chain [SC]

Trimble Cityworks Vulnerability Exploited Against US Local Governments

2025-01-01 [vendor] Trimble Cityworks (GIS asset/work-order management) [cve] CVE-2025-0994
Vector: Attackers exploited a deserialization vulnerability in Trimble Cityworks, a GIS-based work order and asset management system used by local governments, to gain unauthorized access to municipal infrastructure systems

Beginning in early 2025, threat actors exploited CVE-2025-0994, a critical deserialization vulnerability in Trimble Cityworks, to compromise GIS asset and work-order management …

Supply chain [SC]

PowerSchool SIS data breach — 62 million students and 9.5 million educators

2024-12-19 [vendor] PowerSchool Student Information System (SIS) / PowerSource customer portal
Vector: CWE-287: Improper Authentication (stolen/compromised credentials for PowerSource customer support portal; no mandatory MFA)

Attacker (later identified as Massachusetts college student Matthew D. Lane, 19) used compromised credentials to access PowerSchool's PowerSource support portal on 19 December …

Supply chain [SC]

Ultralytics YOLO PyPI Package Supply Chain Attack

2024-12-04 [vendor] GitHub Actions; PyPI [malware] XMRig (Monero cryptominer)
Vector: Attacker abused GitHub Actions by crafting malicious git branch names in pull requests to exfiltrate PyPI publish tokens from the CI/CD runner environment; then published backdoored package versions to PyPI

The popular Ultralytics YOLO AI/ML library (60M+ downloads, 30K+ GitHub stars) was backdoored on 4 December 2024. Versions 8.3.41, 8.3.42, 8.3.45, and 8.3.46 deployed XMRig to mine …

Supply chain [SC]

Monument Health Third-Party Breach (December 2024)

2024-12-01 [vendor] Change Healthcare
Vector: Compromise of third-party service provider / vendor relationship

Nebraska AG’s Lawsuit Against Change Healthcare Survives Motion to Dismiss. A lawsuit filed by Nebraska Attorney General Mike Hilgers over the 2024 Change Healthcare data breach …

Supply chain [SC]

Ascension Health Former Business Partner EHR Data Breach

2024-12-01
Vector: A former business partner of Ascension Health mistakenly included Ascension patient data in a data file sent to a software vendor for testing purposes; that vendor's systems were then compromised by an attacker who accessed the data

Ascension Health disclosed in April 2025 a second security incident, separate from the May 2024 Black Basta ransomware attack. This breach involved a former business partner that …

Supply chain [SC]

Cleo MFT zero-day exploitation by Clop ransomware (CVE-2024-50623 / CVE-2024-55956)

2024-11-15 [vendor] Cleo Harmony, VLTrader, and LexiCom managed file transfer software (versions before 5.8.0.21 / 5.8.0.24) [malware] Clop (Cl0p) ransomware [cve] CVE-2024-50623 +1
Vector: CWE-434: Unrestricted Upload of File with Dangerous Type (CVE-2024-50623 / CVE-2024-55956 — unauthenticated file write vulnerability in Cleo Harmony, VLTrader, and LexiCom MFT software enabling RCE)

Clop ransomware group exploited CVE-2024-50623 in Cleo's MFT products starting November 2024, bypassing the initial patch. Huntress identified active exploitation 3 December 2024 …

Supply chain [SC]

Nokia Third-Party Breach (November 2024)

2024-11-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

Nokia investigates breach after hacker claims to steal source code. Nokia is investigating whether a third-party vendor was breached after a hacker claimed to be selling the …

Supply chain [SC]

Sainsbury's Third-Party Breach (November 2024)

2024-11-01 [vendor] Blue Yonder
Vector: Compromise of third-party service provider / vendor relationship

Ransomware attack on software supplier disrupts operations for Starbucks and other retailers. A ransomware attack that hit a major software provider last week caused disruptions …

Supply chain

MUT-8694 npm and PyPI Malicious Package Campaign

2024-10-10 [vendor] npm registry; PyPI [malware] Blank Grabber infostealer; Skuld Stealer
Vector: Typosquatting: malicious packages uploaded to npm and PyPI mimicking legitimate library names to trick developers into installing them

Datadog Security Labs identified a coordinated supply chain attack campaign (tracked as MUT-8694) active from at least October 10, 2024, targeting both the npm and PyPI package …

Supply chain [SC]

ADT Third-Party Breach (October 2024)

2024-10-01 [vendor] Third-party business partner
Vector: Compromise of third-party service provider / vendor relationship

ADT discloses second breach in 2 months, hacked via stolen credentials. Home and small business security company ADT disclosed it suffered a breach after threat actors gained …

Supply chain [SC]

CF Medical Third-Party Breach (October 2024)

2024-10-01 [vendor] Financial Business and Consumer Solutions (FBCS)
Vector: Compromise of third-party service provider / vendor relationship

Comcast says customer data stolen in ransomware attack on debt collection agency | TechCrunch. The ransomware attack on a U.S. debt collection agency also affects customers of CF …

Supply chain [SC]

Rackspace Third-Party Breach (October 2024)

2024-10-01 [vendor] ScienceLogic
Vector: Compromise of third-party service provider / vendor relationship

Rackspace monitoring data stolen in ScienceLogic zero-day attack. Cloud hosting provider Rackspace suffered a data breach exposing "limited" customer monitoring data after threat …

Supply chain [SC]

Cultura Third-Party Breach (September 2024)

2024-09-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

Popular French retailers confirm hackers stole customer data. Targets of the cyberattacks include electronics and home appliances store Boulanger and the retailer Cultura. Several …

Supply chain [SC]

NHS England Third-Party Breach (September 2024)

2024-09-01 [vendor] Synnovis
Vector: Compromise of third-party service provider / vendor relationship

Data on nearly 1 million NHS patients leaked online following ransomware attack on London hospitals. The stolen data, which was published in June by the Qilin ransomware gang, …

Supply chain [SC]

T-Mobile Third-Party Breach (September 2024)

2024-09-01 [vendor] Capgemini
Vector: Compromise of third-party service provider / vendor relationship

T-Mobile’s VM logs allegedly leaked in 20 GB Capgemini data breach. The attacker claims to have stolen databases, source code, credentials, private keys, as well as log files …

Supply chain [SC]

Toyota Third-Party Breach (August 2024)

2024-08-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

Toyota confirms third-party data breach impacting customers. Toyota confirmed that customer data was exposed in a third-party data breach after a threat actor leaked an archive of …

Supply chain [SC]

300 small Indian banks Third-Party Breach (July 2024)

2024-07-01 [vendor] C-Edge Technologies Ltd
Vector: Compromise of third-party service provider / vendor relationship

Small Indian banks hit by ransomware attack; NPCI suspends payment. Ransomware attack on C-Edge impacts banking services, but no financial loss reported; restoration work underway. …

Supply chain [SC]

AutoNation Third-Party Breach (July 2024)

2024-07-01 [vendor] CDK Global
Vector: Compromise of third-party service provider / vendor relationship

Car dealership company AutoNation says CDK ransomware incident cut into quarterly earnings. AutoNation alerted investors that earnings per share would be down about a one-third …

Supply chain [SC]

Bilt Third-Party Breach (July 2024)

2024-07-01 [vendor] Evolve Bank & Trust
Vector: Compromise of third-party service provider / vendor relationship

Affirm says cardholders impacted by Evolve Bank data breach. Buy now, pay later loan company Affirm is warning that holders of its payment cards had their personal information …

Supply chain [SC]

Clear Spring Health Third-Party Breach (July 2024)

2024-07-01 [vendor] Change Healthcare
Vector: Compromise of third-party service provider / vendor relationship

SouthCoast Health; Call 4 Health Notify Patients About Cyberattacks. SouthCoast Health and Privia Medical Group in Georgia have notified patients about a cyberattack and HIPAA …

Supply chain [SC]

Gemini Third-Party Breach (July 2024)

2024-07-01 [vendor] Not disclosed Automated Clearing House (ACH) service provider
Vector: Compromise of third-party service provider / vendor relationship

Crypto exchange Gemini discloses third-party data breach. Cryptocurrency exchange Gemini is warning it suffered a data breach incident caused by a cyberattack at its Automated …

Supply chain [SC]

Roblox Third-Party Breach (July 2024)

2024-07-01 [vendor] FNTech
Vector: Compromise of third-party service provider / vendor relationship

Roblox vendor data breach exposes dev conference attendee info. Roblox announced late last week that it suffered a data breach impacting attendees of the 2022, 2023, and 2024 …

Supply chain [SC]

TriZetto (Cognizant) Healthcare Technology Breach (3M+ Individuals)

2024-07-01 [vendor] TriZetto (Cognizant subsidiary) — healthcare benefits/RCM software
Vector: Attackers breached TriZetto's healthcare data platform systems, exfiltrating data for health insurance customers that had been processed through TriZetto's revenue cycle management and benefits administration software

TriZetto, a healthcare technology subsidiary of Cognizant Technology Solutions, disclosed in late 2024 that a data breach had affected over 3 million individuals. TriZetto provides …

Supply chain [SC]

Aptihealth Third-Party Breach (June 2024)

2024-06-01 [vendor] Sisense
Vector: Compromise of third-party service provider / vendor relationship

Almost 20,000 Aptihealth Patients Affected by Business Associate Data Breach. Data breaches have been announced by the behavioral health engagement company Aptihealth and the civil …

Supply chain [SC]

Geisinger Third-Party Breach (June 2024)

2024-06-01 [vendor] Nuance Communications
Vector: Compromise of third-party service provider / vendor relationship

Former IT employee accessed data of over 1 million US patients. Geisinger, a prominent healthcare system in Pennsylvania, has announced a data breach involving a former employee of …

Supply chain [SC]

IACT Health Third-Party Breach (June 2024)

2024-06-01 [vendor] Advarra
Vector: Compromise of third-party service provider / vendor relationship

Patient Data Exposed in Cyberattacks on PruittHealth & Easterseals Central Illinois. PruittHealth has notified patients about a November 2023 ransomware attack and has confirmed …

Supply chain [SC]

Newton Centre Dental Third-Party Breach (June 2024)

2024-06-01 [vendor] Affinity Dental Management
Vector: Compromise of third-party service provider / vendor relationship

Email Breach Affects 10,000 University of Chicago Medical Center Patients. Hackers gained access to the email accounts of University of Chicago Medical Center employees and the …

Supply chain [SC]

T-Mobile Third-Party Breach (June 2024)

2024-06-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

T-Mobile denies it was hacked, links leaked data to vendor breach. T-Mobile has denied it was breached or that source code was stolen after a threat actor claimed to be selling …

Supply chain [SC]

HSBC Third-Party Breach (May 2024)

2024-05-01 [vendor] Baton Systems
Vector: Compromise of third-party service provider / vendor relationship

Alleged HSBC, Barclays data exposed by IntelBroker. Hackread reports that IntelBroker has exposed sensitive data allegedly stolen from major UK-based international financial …

Supply chain [SC]

MediSecure Third-Party Breach (May 2024)

2024-05-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

MediSecure e-script firm hit by ‘large-scale’ ransomware data breach. Electronic prescription provider MediSecure in Australia has shut down its website and phone lines following a …

Supply chain [SC]

Cisco Duo Third-Party Breach (April 2024)

2024-04-01 [vendor] Unknown Telephony Provider
Vector: Compromise of third-party service provider / vendor relationship

Cisco Duo warns third-party data breach exposed SMS MFA logs. Cisco Duo's security team warns that hackers stole some customers' VoIP and SMS logs for multi-factor authentication …

Supply chain [SC]

Department of Justice Third-Party Breach (April 2024)

2024-04-01 [vendor] Greylock McKinnon Associates
Vector: Compromise of third-party service provider / vendor relationship

DOJ data on 341,000 people leaked in cyberattack on consulting firm. Medicare and other information belonging to 341,000 people was leaked after a consulting firm working with the …

Supply chain [SC]

Moffitt Cancer Center Third-Party Breach (April 2024)

2024-04-01 [vendor] Gunster Yoakley and Stewart PA
Vector: Compromise of third-party service provider / vendor relationship

Medusa Ransomware Group Leaks Data Stolen from American Renal Associates. The Medusa ransomware group has leaked data stolen from American Renal Associates. Moffitt Cancer Center …

Supply chain [SC]

JetBrains TeamCity CVE-2024-27198 Authentication Bypass — Mass Exploitation

2024-03-04 [vendor] JetBrains TeamCity (CI/CD server and build management platform) [malware] Various backdoors and remote access tools deployed by exploiting actors [cve] CVE-2024-27198 +1
Vector: Authentication bypass vulnerability (CVE-2024-27198, CVSS 9.8) in JetBrains TeamCity CI/CD server allowed unauthenticated remote attackers to gain administrative access to TeamCity build servers; a second vulnerability (CVE-2024-27199, CVSS 7.3) allowed path traversal; multiple threat actors exploited these within hours of Rapid7's public disclosure, abusing admin access to plant backdoors in CI/CD pipelines and steal source code, credentials, and build artifacts

On 4 March 2024, JetBrains and Rapid7 (the discoverer) simultaneously disclosed two authentication bypass vulnerabilities in JetBrains TeamCity — a popular CI/CD build server used …

Supply chain [SC]

American Express Third-Party Breach (March 2024)

2024-03-01 [vendor] A Merchant Processor
Vector: Compromise of third-party service provider / vendor relationship

American Express credit cards exposed in third-party data breach. American Express is warning customers that credit cards were exposed in a third-party data breach after a merchant …

Supply chain [SC]

Bay Area Anesthesia Third-Party Breach (March 2024)

2024-03-01 [vendor] Bowden Barlow Law, P.A.
Vector: Compromise of third-party service provider / vendor relationship

Grace Lutheran Communities Falls Victim of ALPHV/Blackcat Ransomware Attack. Grace Lutheran Communities in Wisconsin, a provider of rehabilitation services, assisted living, …

Supply chain [SC]

Fidelity Third-Party Breach (March 2024)

2024-03-01 [vendor] Infosys McCamish Systems (IMS)
Vector: Compromise of third-party service provider / vendor relationship

First BofA, Now Fidelity: Same Vendor Behind Third-Party Breaches. The private information of more than 28,000 people may have been accessed by unauthorized actors, thanks to a …

Supply chain [SC]

TechCrunch

2024-03-01 [vendor] Mintlify documentation platform
Vector: CWE-312: Cleartext Storage of Sensitive Information (OAuth tokens stored in database)

Mintlify, an AI-powered code documentation platform used by software developers, suffered a breach on March 1, 2024. A vulnerability in Mintlify's systems allowed unauthorized …

Supply chain [SC]

Swiss Goverment Third-Party Breach (March 2024)

2024-03-01 [vendor] Xplain
Vector: Compromise of third-party service provider / vendor relationship

Switzerland: Play ransomware leaked 65,000 government documents. The National Cyber Security Centre (NCSC) of Switzerland has released a report on its analysis of a data breach …

Supply chain [SC]

Akamai / CrowdStrike / Wikipedia / Datadog Security Labs

2024-02-24 [cve] CVE-2024-3094
Vector: CWE-506: Embedded Malicious Code (multi-year social engineering to gain maintainer status, then injected SSH backdoor into xz-utils)

CVSS 10.0. Suspected nation-state actor 'Jia Tan' (JiaT75) spent 2+ years cultivating trust in xz-utils project before becoming co-maintainer. Injected SSH authentication …

Supply chain [SC]

Audiens Third-Party Breach (February 2024)

2024-02-01 [vendor] Viamedis
Vector: Compromise of third-party service provider / vendor relationship

Data breach at French healthcare services firm puts millions at risk. French healthcare services firm Viamedis suffered a cyberattack that exposed the data of policyholders and …

Ransomware [SC]

TietoEVRY Ransomware Attack (Swedish Universities, Municipalities, Companies)

2024-01-19 [vendor] TietoEVRY (cloud hosting and IT services) [malware] Akira ransomware
Vector: Akira ransomware group deployed ransomware against TietoEVRY's Sweden-based cloud hosting platform, impacting one of TietoEVRY's datacenters and disrupting cloud services for dozens of Swedish customers

On January 19-20, 2024, TietoEVRY, a Finnish-Norwegian IT company and one of the largest IT service providers in the Nordics, suffered an Akira ransomware attack against its …

Supply chain [SC]

Family Healthcare Third-Party Breach (January 2024)

2024-01-01 [vendor] Brady Martz & Associates
Vector: Compromise of third-party service provider / vendor relationship

Singing River Health System Confirms Ransomware Attack Affected 895,000 Patients. Singing River Health System has confirmed that 895,204 individuals were affected by an August 2023 …

Supply chain [SC]

Framework Computer Third-Party Breach (January 2024)

2024-01-01 [vendor] Keating Consulting Group
Vector: Compromise of third-party service provider / vendor relationship

Framework discloses data breach after accountant gets phished. Framework Computer disclosed a data breach exposing the personal information of an undisclosed number of customers …

Supply chain [SC]

Primula Third-Party Breach (January 2024)

2024-01-01 [vendor] Tietoevry
Vector: Compromise of third-party service provider / vendor relationship

Akira ransomware hits cloud service Tietoevry; numerous Swedish customers affected. Finland-based Tietoevry said “one part of one of our Swedish datacenters” was attacked with …

Supply chain [SC]

Uppsala County Third-Party Breach (January 2024)

2024-01-01 [vendor] TietoEVRY
Vector: Compromise of third-party service provider / vendor relationship

Tietoevry ransomware attack causes outages for Swedish firms, cities. Finnish IT services and enterprise cloud hosting provider Tietoevry has suffered an Akira ransomware attack …

Supply chain [SC]

Ledger Connect Kit Supply Chain Attack — DRAINER injected via compromised npm account

2023-12-14 [vendor] Ledger Connect Kit (@ledgerhq/connect-kit npm package) [malware] Angel Drainer (cryptocurrency wallet drainer injected via CDN)
Vector: Former Ledger employee's NPMJS account was compromised via a targeted phishing attack after the employee left the company; attacker used the account to publish malicious versions (1.1.5, 1.1.6, 1.1.7) of the @ledgerhq/connect-kit package — a widely integrated JavaScript library that enables hardware wallet connections in DeFi front-ends — replacing the legitimate code with a wallet drainer that redirected cryptocurrency transactions to attacker-controlled addresses

On 14 December 2023, an attacker compromised the npm account of a former Ledger employee (whose account retained access to the @ledgerhq/connect-kit package despite employment …

Supply chain [SC]

Tweet thread by bantg

2023-12-14 [vendor] Ledger supply chain attack [loss] $610,000
Vector: Software supply chain attack

A supply chain attack on the Ledger connector application has rippled throughout the world of decentralized apps, which widely use the software to enable people to connect their …

Supply chain [SC]

Dollar Tree Third-Party Breach (November 2023)

2023-11-01 [vendor] Zeroed-In Technologies
Vector: Compromise of third-party service provider / vendor relationship

Dollar Tree hit by third-party data breach impacting 2 million people. Discount store chain Dollar Tree was impacted by a third-party data breach affecting 1,977,486 people after …

Supply chain [SC]

Northwell Health Third-Party Breach (November 2023)

2023-11-01 [vendor] Perry Johnson & Associates, Inc., (PJ&A)
Vector: Compromise of third-party service provider / vendor relationship

Console & Associates, P.C.: PJ&A Reports Data Breach Exposing Social Security Numbers and PHI of an Unknown Number of Northwell Health Patients. /PRNewswire/ -- Millions of …

Supply chain [SC]

Sutter Health Third-Party Breach (November 2023)

2023-11-01 [vendor] Virgin Pulse
Vector: Compromise of third-party service provider / vendor relationship

Sutter Health Confirms 84K Individuals Affected by Cyberattack on Business Associate. Sutter Health, a healthcare provider serving Northern California, has recently confirmed that …

Supply chain [SC]

Taylor Rose Third-Party Breach (November 2023)

2023-11-01 [vendor] CTS
Vector: Compromise of third-party service provider / vendor relationship

EYE NEWSFLASH: Major ‘cybersecurity issue’ preventing transactions progressing - Property Industry Eye. EYE NEWSFLASH: Major ‘cybersecurity issue’ preventing transactions …

Supply chain [SC]

Westat, Inc. Third-Party Breach (November 2023)

2023-11-01 [vendor] Nuance Communications, Inc.
Vector: Compromise of third-party service provider / vendor relationship

Westat. Notice of data security incident affecting Renown Health patient information. Learn about the MOVEit vulnerability and credit monitoring. Third-party company: Nuance …

Supply chain [SC]

Arietis Health Third-Party Breach (October 2023)

2023-10-01 [vendor] Ipswitch, Inc.
Vector: Compromise of third-party service provider / vendor relationship

RCM Company Reports Data Breach Tied to MOVEit Software, 1.9M Impacted | TechTarget. The revenue cycle management company reported a data breach that impacted more than 1.9 million …

Supply chain [SC]

Cook County Health Third-Party Breach (October 2023)

2023-10-01 [vendor] Perry Johnson & Associates, Inc., (PJ&A)
Vector: Compromise of third-party service provider / vendor relationship

Cook County Health Patients Affected by Cyberattack at Medical Transcription Firm. Cook County Health, which operates John H. Stroger, Jr. Hospital and Provident Hospital in …

Supply chain [SC]

Humana Inc. Third-Party Breach (October 2023)

2023-10-01 [vendor] PNC Bank
Vector: Compromise of third-party service provider / vendor relationship

Cyberattacks Reported by Brooklyn Premier Orthopedics & Atlas Healthcare. Brooklyn Premier Orthopedics (BPO) in New York has confirmed the protected health information of 48,459 …

Supply chain [SC]

SA Health Third-Party Breach (October 2023)

2023-10-01 [vendor] Personify Care
Vector: Compromise of third-party service provider / vendor relationship

SA patient health info deleted in third-party app breach. [](https://www.linkedin.com/company/itnews "follow us on Linkedin")[](https://twitter.com/itnews_au "follow us on …

Supply chain [SC]

Sony Third-Party Breach (October 2023)

2023-10-01 [vendor] Ipswitch, Inc.
Vector: Compromise of third-party service provider / vendor relationship

Sony confirms data breach impacting thousands in the U.S.. Sony Interactive Entertainment (Sony) has notified current and former employees and their family members about a …

Supply chain [SC]

Super SA Third-Party Breach (October 2023)

2023-10-01 [vendor] Former external service provider
Vector: Compromise of third-party service provider / vendor relationship

Super SA discloses third-party data breach. [](https://www.linkedin.com/company/itnews "follow us on Linkedin")[](https://twitter.com/itnews_au "follow us on …

Supply chain [SC]

890 Schools Third-Party Breach (September 2023)

2023-09-01 [vendor] National Student Clearinghouse (NSC)
Vector: Compromise of third-party service provider / vendor relationship

National Student Clearinghouse data breach impacts 890 schools. U.S. educational nonprofit National Student Clearinghouse has disclosed a data breach affecting 890 schools using …

Supply chain [SC]

Airbus Third-Party Breach (September 2023)

2023-09-01 [vendor] Turkish Airlines
Vector: Compromise of third-party service provider / vendor relationship

Airbus investigates data leak allegedly involving thousands of suppliers. The European aerospace giant Airbus said on Tuesday that it is investigating a cybersecurity incident …

Supply chain [SC]

Amerita Third-Party Breach (September 2023)

2023-09-01 [vendor] PharMerica
Vector: Compromise of third-party service provider / vendor relationship

Amerita Notifies Nearly 220K of PharMerica Data Breach | TechTarget. MedMinder Systems and PurFoods also reported healthcare data breaches recently. Amerita, a specialty infusion …

Supply chain [SC]

BORN Ontario Third-Party Breach (September 2023)

2023-09-01 [vendor] Ipswitch, Inc.
Vector: Compromise of third-party service provider / vendor relationship

SickKids impacted by BORN Ontario data breach that hit 3.4 million. The Hospital for Sick Children, more commonly known as SickKids, is among healthcare providers that were …

Supply chain [SC]

FTX Third-Party Breach (September 2023)

2023-09-01 [vendor] Kroll Inc.
Vector: Compromise of third-party service provider / vendor relationship

Kroll data breach exposes info of FTX, BlockFi, Genesis creditors. Multiple reports on social media warn of a data breach at financial and risk advisory company Kroll that resulted …

Supply chain [SC]

Dollar Tree/Family Dollar — Zeroed-In Technologies Breach (1.98M)

2023-08-07 [vendor] Zeroed-In Technologies HR analytics platform
Vector: Zeroed-In Technologies, an HR analytics vendor used by Dollar Tree and Family Dollar, suffered a data breach affecting its systems — attackers accessed systems and stole employee data; Dollar Tree and its subsidiary Family Dollar were downstream victims

Dollar Tree and its subsidiary Family Dollar disclosed in November 2023 that Zeroed-In Technologies, a third-party HR analytics vendor they used, suffered a data breach between …

Supply chain [SC]

Zillow Third-Party Breach (August 2023)

2023-08-01 [vendor] Rapattoni Corporation
Vector: Compromise of third-party service provider / vendor relationship

Ransomware Hit Disrupts Real Estate Property Listings in US. Property listings nationwide are being disrupted due to an apparent ransomware attack against California-based …

Supply chain [SC]

Postbank Third-Party Breach (July 2023)

2023-07-01 [vendor] Majorel
Vector: Compromise of third-party service provider / vendor relationship

Datenleck bei Postbank und Deutscher Bank / Kriminelle kopieren Bankdaten. Lahr (ots) - Hacker haben Daten von Kunden der Deutschen Bank bei einem Datenleck gestohlen. Auch die …

Supply chain [SC]

CoxHealth Third-Party Breach (June 2023)

2023-06-01 [vendor] Intellihartx LLC
Vector: Compromise of third-party service provider / vendor relationship

UPMC contractor detects patient data breach. A contractor for UPMC said it discovered a data breach that could have impacted customer and patient information. Tennessee-based …

Supply chain [SC]

DHL Third-Party Breach (June 2023)

2023-06-01 [vendor] Ipswitch, Inc.
Vector: Compromise of third-party service provider / vendor relationship

Extreme Networks emerges as victim of Clop MOVEit attack | Computer Weekly. Network equipment and services supplier Extreme Networks has revealed its instance of Progress …

Supply chain [SC]

Dublin Airport Third-Party Breach (June 2023)

2023-06-01 [vendor] Aon
Vector: Compromise of third-party service provider / vendor relationship

Dublin Airport staff pay data hit by criminals. Attackers accessed it via third-party services provider, says management group. It's an awkward Monday for Dublin Airport after pay …

Supply chain [SC]

Exeter Finance Third-Party Breach (June 2023)

2023-06-01 [vendor] NCB Management Services, Inc.
Vector: Compromise of third-party service provider / vendor relationship

Capital One becomes latest bank affected by cyberattack on debt-buying giant. The initial response to the incident focused on former customers of Bank of America, but Capital One …

Supply chain [SC]

Majorel Third-Party Breach (June 2023)

2023-06-01 [vendor] Ipswitch, Inc.
Vector: Compromise of third-party service provider / vendor relationship

MOVEit attack on Aon exposed data of the staff at the Dublin Airport. [](https://www.facebook.com/sec.affairs/)[](https://twitter.com/securityaffairs). UAT-10362 linked to …

Supply chain [SC]

Southwest Airlines Third-Party Breach (June 2023)

2023-06-01 [vendor] Pilot Credentials
Vector: Compromise of third-party service provider / vendor relationship

American Airlines, Southwest Airlines disclose data breaches affecting pilots. American Airlines and Southwest Airlines, two of the largest airlines in the world, disclosed data …

Supply chain [SC]

TJ Maxx Third-Party Breach (June 2023)

2023-06-01 [vendor] Ipswitch, Inc.
Vector: Compromise of third-party service provider / vendor relationship

media-center press-releases 2023 07 14 hillsborough-notifies-residents-vendors-of-global-data-breach. Skip to main content Enable accessibility for low vision Open the …

Supply chain [SC]

CISA Advisory AA23-158A / Mandiant / Wikipedia

2023-05-27 [vendor] Progress Software MOVEit Transfer [malware] LEMURLOOT web shell [cve] CVE-2023-34362 +1
Vector: CWE-89: SQL Injection in MOVEit Transfer web application

CL0P ransomware gang exploited a zero-day SQL injection in Progress Software's MOVEit Transfer MFT product starting May 27 2023. Installed LEMURLOOT web shell to steal data. Over …

Supply chain [SC]

Welltok Healthcare SaaS MOVEit Breach — 8.5 Million Patient Records

2023-05-27 [vendor] Welltok MOVEit Transfer / patient health engagement SaaS platform [malware] Cl0p ransomware [cve] CVE-2023-34362
Vector: Cl0p ransomware group exploited CVE-2023-34362 (MOVEit Transfer SQL injection zero-day) against Welltok's MOVEit Transfer server; Welltok used MOVEit Transfer to transfer patient data files on behalf of healthcare clients including major US health plans

Welltok, Inc. — a healthcare SaaS company providing patient health engagement and communication services to major US health plans — was among the largest individual victims of the …

Supply chain [SC]

HIPAA Journal / BleepingComputer / SEC 8-K filing

2023-05-27 [vendor] Progress Software MOVEit Transfer / Maximus government services [malware] LEMURLOOT web shell [cve] CVE-2023-34362
Vector: CWE-89: SQL Injection in MOVEit Transfer web application (zero-day)

Maximus Inc. (US government contractor managing Medicare, Medicaid, student loan programs) was the largest single victim of Cl0p's MOVEit campaign. SEC 8-K filed July 26 2023 …

Supply chain [SC]

Coles Third-Party Breach (May 2023)

2023-05-01 [vendor] Latitude Financial Services
Vector: Compromise of third-party service provider / vendor relationship

Coles confirms its customers impacted by Latitude Financial data breach. Supermarket giant Coles has confirmed it has been impacted by the Latitude Financial data breach, saying …

Supply chain [SC]

Intel Third-Party Breach (May 2023)

2023-05-01 [vendor] Micro Star International (MSI)
Vector: Compromise of third-party service provider / vendor relationship

Intel investigating leak of Intel Boot Guard private keys after MSI breach. Intel is investigating the leak of alleged private keys used by the Intel BootGuard security feature, …

Supply chain [SC]

Iowa Medicaid Third-Party Breach (May 2023)

2023-05-01 [vendor] Telligen, Inc.
Vector: Compromise of third-party service provider / vendor relationship

ILS Data Breach Affects Almost 21K Iowan Medicaid Recipients. The Iowa Department of Health and Human Services (DHHS) has confirmed a HIPAA compliance breach where the personal …

Supply chain [SC]

Kibble Equipment Third-Party Breach (May 2023)

2023-05-01 [vendor] Razor Consulting Solutions
Vector: Compromise of third-party service provider / vendor relationship

Kibble Equipment Data Breach Investigation – Turke & Strauss LLP. Turke & Strauss LLP, a leading data breach law firm, is investigating Kibble Equipment, LLC and its vendors, Razor …

Supply chain [SC]

Paramount Health Care Third-Party Breach (May 2023)

2023-05-01 [vendor] NationsBenefits Holding, LLC
Vector: Compromise of third-party service provider / vendor relationship

IL, KY, and TN Healthcare Orgs Recovering from Recent Cyberattacks. Morris Hospital & Healthcare Centers Investigating Royal Ransomware Attack Morris Hospital & Healthcare Centers …

Supply chain [SC]

VCU Health System Third-Party Breach (May 2023)

2023-05-01 [vendor] Credit Control Corporation
Vector: Compromise of third-party service provider / vendor relationship

Debt Collection Agency Data Breach Affects 345,523 Individuals. R&B Corporation of Virginia, doing business as Credit Control Corporation (CCC), has recently reported a data breach …

Supply chain [SC]

Webster Bank Third-Party Breach (May 2023)

2023-05-01 [vendor] Guardian Analytics, Inc.
Vector: Compromise of third-party service provider / vendor relationship

Webster Bank Reports Third-Party Data Breach at Guardian Analytics, Inc. | JD Supra. On April 10, 2023, Webster Bank filed a notice of data breach with the Maine Attorney General …

Supply chain [SC]

Whitman College Third-Party Breach (May 2023)

2023-05-01 [vendor] Brightline Health
Vector: Compromise of third-party service provider / vendor relationship

Brightline: At Least 964,300 Individuals Affected by Fortra GoAnywhere Hack. Brightline, a provider of virtual behavioral and mental services to families, has confirmed it was …

Supply chain [SC]

Mandiant / Google Cloud Blog / Krebs on Security

2023-03-16 [vendor] 3CX DesktopApp [malware] SUDDENICON downloader / ICONICSTEALER infostealer [cve] CVE-2023-29059
Vector: CWE-506: Embedded Malicious Code (malicious DLL sideloaded into 3CX DesktopApp installer; itself seeded via poisoned Trading Technologies X_TRADER installer)

Lazarus Group (North Korea, subunit Labyrinth Chollima) trojanized 3CX DesktopApp versions 18.12.407 and 18.12.416 for Windows and Mac. Delivered SUDDENICON downloader which …

Supply chain [SC]

AT&T Third-Party Breach (March 2023)

2023-03-01 [vendor] Unknown
Vector: Compromise of third-party service provider / vendor relationship

AT&T alerts 9 million customers of data breach after vendor hack. AT&T is notifying roughly 9 million customers that some of their information has been exposed after one of its …

Supply chain [SC]

Cornell University, Ithaca College, Virginia Tech University, SUNY Oswego, Colorado State University, Loyola University Chicago and McMaster University Third-Party Breach (March 2023)

2023-03-01 [vendor] AudienceView
Vector: Compromise of third-party service provider / vendor relationship

Students' bank accounts hacked because of ticketing software breach - The Ithacan. After attending a concert at Cornell University featuring Beach Bunny on Jan. 28, several Ithaca …

Supply chain [SC]

Uber Third-Party Breach (March 2023)

2023-03-01 [vendor] Genova Burns
Vector: Compromise of third-party service provider / vendor relationship

Uber suffers another data breach after law firm’s servers attacked. This is the third time in six months that Uber has been the victim of a data breach. Uber has found itself in …

Supply chain [SC]

Boost Mobile Third-Party Breach (February 2023)

2023-02-01 [vendor] DISH Network Corporation
Vector: Compromise of third-party service provider / vendor relationship

The Week in Ransomware - March 3rd 2023 - Wide impact attacks. This week was highlighted by a massive BlackBasta ransomware attack targeting DISH Network and taking down numerous …

Supply chain [SC]

Sling TV Third-Party Breach (February 2023)

2023-02-01 [vendor] DISH Network Corporation
Vector: Compromise of third-party service provider / vendor relationship

Dish confirms ransomware attack allowed hackers to steal personal data | TechCrunch. Dish said a ransomware attack is to blame for an ongoing, multiday outage and warned that …

Supply chain [SC]

Hatch Bank GoAnywhere MFT Breach (Cl0p, CVE-2023-0669)

2023-01-30 [vendor] Fortra GoAnywhere Managed File Transfer (MFT) [malware] Cl0p [cve] CVE-2023-0669
Vector: Cl0p exploited CVE-2023-0669, a pre-authentication remote code injection vulnerability in Fortra's GoAnywhere MFT administrative interface, to access Hatch Bank's file transfer environment on January 30–31, 2023 and steal customer names and Social Security numbers

Hatch Bank, a fintech-focused bank-as-a-service provider headquartered in San Francisco, was an early confirmed victim of the Cl0p ransomware group's mass exploitation of …

Supply chain [SC]

Community Health Systems GoAnywhere MFT Breach (Cl0p, CVE-2023-0669)

2023-01-28 [vendor] Fortra GoAnywhere Managed File Transfer (MFT) [malware] Cl0p [cve] CVE-2023-0669
Vector: Cl0p exploited CVE-2023-0669, a pre-authentication remote code injection vulnerability in Fortra's GoAnywhere MFT administrative interface, to exfiltrate data from Community Health Systems' managed file transfer environment between January 28–30, 2023; no ransomware encryption was deployed — data theft only

Community Health Systems (CHS), one of the largest for-profit hospital operators in the United States, was among the earliest publicly disclosed victims of Cl0p's mass-exploitation …

Supply chain [SC]

BleepingComputer / Fortra / CISA

2023-01-18 [vendor] Fortra GoAnywhere MFT [cve] CVE-2023-0669
Vector: CWE-78: OS Command Injection (pre-auth RCE in GoAnywhere MFT admin interface)

Cl0p exploited zero-day RCE in Fortra GoAnywhere MFT admin portal. ~130 organizations breached over 10 days in January 2023. Cl0p named 100+ victims on leak site through March …

Supply chain [SC]

Fortra GoAnywhere MFT Zero-Day Cl0p Exploitation — CVE-2023-0669, 130+ Organizations

2023-01-18 [vendor] Fortra GoAnywhere Managed File Transfer (MFT) [malware] Cl0p; Truebot web shell
Vector: Cl0p exploited CVE-2023-0669, a pre-authentication remote code injection vulnerability in Fortra GoAnywhere MFT's administrative interface; attackers installed a web shell ('Truebot') and exfiltrated data before the vulnerability was publicly known

Beginning 18 January 2023, Cl0p exploited a zero-day (CVE-2023-0669) in Fortra's GoAnywhere MFT, claiming to have breached approximately 130 organizations over 10 days before …

Supply chain [SC]

Fortra GoAnywhere MFT Zero-Day Cl0p Exploitation — CVE-2023-0669, 130+ Organizations

2023-01-18 [vendor] Fortra GoAnywhere Managed File Transfer (MFT) [malware] Cl0p; Truebot web shell
Vector: Cl0p exploited CVE-2023-0669, a pre-authentication remote code injection vulnerability in Fortra GoAnywhere MFT's administrative interface; attackers installed a web shell ('Truebot') and exfiltrated data before the vulnerability was publicly known

Beginning 18 January 2023, Cl0p exploited a zero-day (CVE-2023-0669) in Fortra's GoAnywhere MFT, claiming to have breached approximately 130 organizations over 10 days before …

Supply chain [SC]

Fortra GoAnywhere MFT Zero-Day Cl0p Exploitation — CVE-2023-0669, 130+ Organizations

2023-01-18 [vendor] Fortra GoAnywhere Managed File Transfer (MFT) [malware] Cl0p; Truebot web shell
Vector: Cl0p exploited CVE-2023-0669, a pre-authentication remote code injection vulnerability in Fortra GoAnywhere MFT's administrative interface; attackers installed a web shell ('Truebot') and exfiltrated data before the vulnerability was publicly known

Beginning 18 January 2023, Cl0p exploited a zero-day (CVE-2023-0669) in Fortra's GoAnywhere MFT, claiming to have breached approximately 130 organizations over 10 days before …

Supply chain [SC]

Fortra GoAnywhere MFT Zero-Day Cl0p Exploitation — CVE-2023-0669, 130+ Organizations

2023-01-18 [vendor] Fortra GoAnywhere Managed File Transfer (MFT) [malware] Cl0p; Truebot web shell
Vector: Cl0p exploited CVE-2023-0669, a pre-authentication remote code injection vulnerability in Fortra GoAnywhere MFT's administrative interface; attackers installed a web shell ('Truebot') and exfiltrated data before the vulnerability was publicly known

Beginning 18 January 2023, Cl0p exploited a zero-day (CVE-2023-0669) in Fortra's GoAnywhere MFT, claiming to have breached approximately 130 organizations over 10 days before …

Supply chain [SC]

Fortra GoAnywhere MFT Zero-Day Cl0p Exploitation — CVE-2023-0669, 130+ Organizations

2023-01-18 [vendor] Fortra GoAnywhere Managed File Transfer (MFT) [malware] Cl0p; Truebot web shell
Vector: Cl0p exploited CVE-2023-0669, a pre-authentication remote code injection vulnerability in Fortra GoAnywhere MFT's administrative interface; attackers installed a web shell ('Truebot') and exfiltrated data before the vulnerability was publicly known

Beginning 18 January 2023, Cl0p exploited a zero-day (CVE-2023-0669) in Fortra's GoAnywhere MFT, claiming to have breached approximately 130 organizations over 10 days before …

Supply chain [SC]

KLM Third-Party Breach (January 2023)

2023-01-01 [vendor] Flying Blue
Vector: Compromise of third-party service provider / vendor relationship

Air France and KLM notify customers of account hacks. Air France and KLM have informed Flying Blue customers that some of their personal information was exposed after their …

Supply chain [SC]

PyTorch Nightly Dependency Confusion Attack — torchtriton Malicious Package

2022-12-25 [vendor] PyTorch nightly build (Meta AI deep learning framework) [malware] triton (malicious PyPI package — data stealer)
Vector: Dependency confusion attack: attacker uploaded a malicious package named 'torchtriton' to the public PyPI index that took precedence over the legitimate same-named package in PyTorch's private package index (download.pytorch.org); any user who installed PyTorch nightly builds between 25-30 December 2022 using pip received the malicious torchtriton package which stole sensitive data from the victim's system

On 25 December 2022, an attacker uploaded a malicious package named 'torchtriton' to the public PyPI index. PyTorch nightly builds depended on a package with the same name …

Supply chain [SC]

Sobeys Third-Party Breach (December 2022)

2022-12-01 [vendor] Empire Co.
Vector: Compromise of third-party service provider / vendor relationship

Inside the turmoil at Sobeys-owned stores after ransomware attack | CBC News. Employees of Empire Co., the parent company of Sobeys, have begun to speak out about the turmoil …

Supply chain [SC]

St. Luke's Health Third-Party Breach (December 2022)

2022-12-01 [vendor] Adelanto Healthcare Ventures
Vector: Compromise of third-party service provider / vendor relationship

Third-party breach impacts St. Luke's Health. HealthITSecurity reports that Texas-based St. Luke's Health has disclosed experiencing a third-party data breach involving consulting …

Data leak [SC]

Advocate Aurora Health Web Tracking Pixel Disclosure — 3 Million Patients

2022-10-14 [vendor] Advocate Aurora Health patient web portals (Meta Pixel / Google Analytics)
Vector: Third-party web tracking pixels (Meta Pixel and Google Analytics) embedded in Advocate Aurora Health's patient-facing web portals transmitted protected health information to Meta and Google; the pixels were present on patient scheduling, billing, and MyChart portal pages

Advocate Aurora Health — an integrated health system with 26 hospitals across Wisconsin and Illinois — disclosed in October 2022 that it had notified approximately 3 million …

Supply chain

Barracuda Email Security Gateway Zero-Day CVE-2023-2868 — UNC4841 China APT

2022-10-01 [vendor] Barracuda Email Security Gateway (ESG) hardware appliance [malware] SALTWATER, SEASPY, SEASIDE, SUBMARINE, WHIRLPOOL [cve] CVE-2023-2868
Vector: UNC4841 (China-nexus APT) exploited CVE-2023-2868, a remote command injection zero-day in Barracuda ESG's email attachment scanning module triggered by specially crafted TAR file names sent via email; no authentication or user interaction required — attacker simply emailed malicious attachments to any recipient at a victim organisation using a Barracuda ESG appliance

Beginning in October 2022 (nearly eight months before disclosure), UNC4841 — a China-nexus espionage group assessed by Mandiant as acting in support of Chinese state interests — …

Supply chain [SC]

Anthem MaineHealth Third-Party Breach (September 2022)

2022-09-01 [vendor] Alight.com (Choice Health prev)
Vector: Compromise of third-party service provider / vendor relationship

Anthem MaineHealth Reports Third Party Data Breach Related to Incident at Choice Health | JD Supra. On September 30, 2022, Anthem MaineHealth (“AMH Health”) filed an official …

Supply chain [SC]

Humana Third-Party Breach (September 2022)

2022-09-01 [vendor] Alight.com (Choice Health prev)
Vector: Compromise of third-party service provider / vendor relationship

Humana Announces Reports Third-Party Data Breach Involving Data Security Incident at Choice Health | JD Supra. On September 21, 2022, Humana confirmed that the company experienced …

Supply chain [SC]

Magento Third-Party Breach (September 2022)

2022-09-01 [vendor] FishPig
Vector: Compromise of third-party service provider / vendor relationship

Hackers breach software vendor for Magento supply-chain attacks. Hackers have injected malware in multiple extensions from FishPig, a vendor of Magento-WordPress integrations that …

Supply chain [SC]

Kiplepay Sdn Bhd Third-Party Breach (August 2022)

2022-08-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Kiplepay informs users on potential indirect data breach through third-party payment gateway provider. KUALA LUMPUR: E-wallet service provider Kiplepay Sdn Bhd had informed its …

Supply chain [SC]

NHS Third-Party Breach (August 2022)

2022-08-01 [vendor] Advanced
Vector: Compromise of third-party service provider / vendor relationship

NHS IT supplier held to ransom by hackers. Its IT provider says it may take three or four weeks to fully recover from the cyber-attack. A cyber-attack on a major IT provider of the …

Supply chain [SC]

American Health Imaging, Banner Medical Group, Belle Point Dental, Duck Creek Family Dental, Partners In Periodontics, and 652 organizations Third-Party Breach (July 2022)

2022-07-01 [vendor] Professional Finance Company
Vector: Compromise of third-party service provider / vendor relationship

Ransomware attack one of year's biggest health data breaches. A cyberattack on a little-known debt collection firm affects over 650 healthcare facilities across the U.S. A …

Supply chain [SC]

Arlington Skin Third-Party Breach (July 2022)

2022-07-01 [vendor] Virtual Private Network Solutions
Vector: Compromise of third-party service provider / vendor relationship

First Choice Community Healthcare Data Breach Affects 101,000 Patients. First Choice Community Healthcare in Albuquerque, NM, has started notifying certain patients that an …

Supply chain [SC]

Celsius Third-Party Breach (July 2022)

2022-07-01 [vendor] Customer.io
Vector: Compromise of third-party service provider / vendor relationship

Blockworks. $72.1K $72,120.00 $2.2K $2,214.14 $602.5 $602.46 $84 $83.95 $41.4 $41.37. 24hr Spot DEX Volume $6.03B -0.75%24hr App Revenue $11.81M -0.01%24hr Blockchain REV $229.96M …

Supply chain [SC]

Baptist Health System, Resolute Health Hospital, The Hospitals of Providence Memorial Campus, Valley Baptist Medical Center – Brownsville, Valley Baptist Medical Center – Harlingen Third-Party Breach (June 2022)

2022-06-01 [vendor] Conifer Revenue Cycle Solutions
Vector: Compromise of third-party service provider / vendor relationship

Not Found. Best in Class Identity Protection Services | ID Theft Protection | IDX. Best identity protection services to keep you safe from cyber crime with credit and identity …

Supply chain [SC]

OpenSea Third-Party Breach (June 2022)

2022-06-01 [vendor] Customer.io
Vector: Compromise of third-party service provider / vendor relationship

OpenSea users' email addresses leaked in data breach. If you’ve shared your email address with the NFT marketplace, you should assume to be impacted. The company is working with …

Supply chain [SC]

Priority Health Third-Party Breach (June 2022)

2022-06-01 [vendor] Warner Norcross & Judd
Vector: Compromise of third-party service provider / vendor relationship

120K Priority Health Members Impacted By Third-Party Data Breach | TechTarget. Michigan-based health plan Priority Health notified 120,000 individuals of a third-party data breach …

Supply chain [SC]

EvergreenHealth Third-Party Breach (May 2022)

2022-05-01 [vendor] MyCare
Vector: Compromise of third-party service provider / vendor relationship

Illinois Gastroenterology Group Data Breach Impacts 228K | TechTarget. Optima Dermatology, EvergreenHealth, and SAC Health also faced healthcare data breaches recently. Illinois …

Supply chain [SC]

K12 Schools in NY Third-Party Breach (May 2022)

2022-05-01 [vendor] Illuminate Education
Vector: Compromise of third-party service provider / vendor relationship

Illuminate Education Mega-Breach Affects K-12 Students. New York state officials are investigating a data breach at Illuminate Education, maker of a widely used software platform …

Supply chain [SC]

Mangatoon Third-Party Breach (May 2022)

2022-05-01 [vendor] Elasticsearch
Vector: Compromise of third-party service provider / vendor relationship

Mangatoon data breach exposes data from 23 million accounts. Manga comic reading app Mangatoon has suffered a data breach that exposed the account information of 23 million users …

Supply chain [SC]

St. Luke's Third-Party Breach (May 2022)

2022-05-01 [vendor] Kaye-Smith
Vector: Compromise of third-party service provider / vendor relationship

St. Luke's says customers hit with data breach that may have exposed personal, financial, medical information. St. Luke’s Health System issued a news release Wednesday saying an …

Supply chain [SC]

Dis-Chem Third-Party Breach (April 2022)

2022-04-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Dis-Chem says it won't share more info on data breach that hit 3.6m clients | News24. In April an “unauthorised person” accessed 3.6 million customers’ first names, surnames, email …

Supply chain [SC]

Sunwing Airlines Third-Party Breach (April 2022)

2022-04-01 [vendor] Airline Choice
Vector: Compromise of third-party service provider / vendor relationship

Cyber-Attackers Hit Sunwing Airlines. Thousands of passengers of Canadian low-cost airline face delays after third-party system was hacked. Thousands of passengers of Canadian …

Data leak [SC]

MCG Health Patient Care Guidelines Breach — 1.1 Million Patients

2022-03-25 [vendor] MCG Health patient care guidelines platform
Vector: Unknown attacker gained unauthorized access to MCG Health's IT environment and accessed a file containing patient personal data stored on MCG Health's systems; the specific intrusion vector was not publicly disclosed

In March 2022, MCG Health — a Hearst Health subsidiary providing evidence-based patient care guidelines and clinical decision support software to health plans and hospitals — …

Supply chain [SC]

Acro Third-Party Breach (March 2022)

2022-03-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Web Application Security, Testing, & Scanning - PortSwigger. PortSwigger offers tools for web application security, testing, & scanning. Choose from a range of security tools, & …

Supply chain [SC]

DataHEALTH Third-Party Breach (March 2022)

2022-03-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Data Breach Alert: DataHEALTH, Inc. | JD Supra. Recently, DataHEALTH, Inc. confirmed that certain consumer data was compromised as a result of the company being the target of a …

Supply chain [SC]

Highmark Third-Party Breach (March 2022)

2022-03-01 [vendor] Quantum Group
Vector: Compromise of third-party service provider / vendor relationship

Highmark issues statement on ‘data security incident’ with vendor. [](https://circulation.timesleader.com/product/times-leader-e-edition/). Times Leader Wilkes-Barre, PA News, …

Supply chain [SC]

Rennline Third-Party Breach (March 2022)

2022-03-01 [vendor] Freestyle Solutions
Vector: Compromise of third-party service provider / vendor relationship

Page Not Found | JD Supra. Opens in a new window Opens an external website Opens an external website in a new window. This website utilizes technologies such as cookies to enable …

Supply chain [SC]

Not disclosed Third-Party Breach (February 2022)

2022-02-01 [vendor] Comprehensive Health Services
Vector: Compromise of third-party service provider / vendor relationship

2 Vendor Hacking Incidents Affect Over 600,000 Individuals. Two recent hacking breaches affecting hundreds of thousands of individuals - one reported by a firm that provides …

Supply chain [SC]

Avamere Health Services Third-Party Breach — 75+ Long-Term Care Organizations

2022-01-01 [vendor] Avamere Health Services (managed healthcare services provider)
Vector: Avamere Health Services — a managed services provider for senior living and post-acute care facilities — suffered a ransomware or unauthorized access incident that exposed patient data for 75+ affiliated healthcare organizations

In January-February 2022, Avamere Health Services — a Wilsonville, Oregon-based managed services provider for senior living, skilled nursing, and rehabilitation facilities — …

Supply chain [SC]

Ciox Health Third-Party Breach — Baptist Memorial, Children's Healthcare of Atlanta, Hoag, 28+ Health Systems

2022-01-01 [vendor] Ciox Health (health information management services)
Vector: Ciox Health — a major health information management (HIM) services provider — suffered a phishing-related breach that exposed patient data across 28+ hospital and health system clients

In January 2022, Ciox Health — a major provider of health information management (HIM) services including medi cal record retrieval, release-of-information (ROI), and coding …

Supply chain [SC]

Good Samaritan Society, Mission Healthcare at Renton, Prestige Care, Rockwood South Hill, Kin On Health Care Center, and 63 organizations Third-Party Breach (January 2022)

2022-01-01 [vendor] Infinity Rehab
Vector: Compromise of third-party service provider / vendor relationship

Page not found - Infinity Rehab. [](https://www.facebook.com/InfinityRehabCommunity "Facebook")[](https://twitter.com/infinityrehab "X")[](https://www.instagram.com/infinityrehab/ …

Supply chain [SC]

ICRC (Red Cross) Data Breach via Zoho ManageEngine Vulnerability

2021-11-09 [vendor] Zoho ManageEngine ADSelfService Plus [cve] CVE-2021-40539
Vector: Exploitation of unpatched CVE-2021-40539 in Zoho ManageEngine ADSelfService Plus, enabling unauthenticated remote code execution on ICRC servers hosted by a third-party contractor in Switzerland

On 19 January 2022, the International Committee of the Red Cross (ICRC) disclosed a sophisticated cyberattack that compromised personal data on more than 515,000 highly vulnerable …

Supply chain [SC]

QRS Clients Third-Party Breach (November 2021)

2021-11-01 [vendor] QRS
Vector: Compromise of third-party service provider / vendor relationship

320K Impacted in EHR Vendor Breach, Ransomware Hits Health Systems | TechTarget. Unauthorized email access and ransomware disrupted the operations of other health systems, while nn …

Supply chain [SC]

Uber Eats Data Exposed via Third Party — 820,000 Delivery Drivers' Data

2021-11-01 [vendor] Uber Eats third-party marketing vendor systems
Vector: A third-party vendor contracted by Uber to provide marketing services to Uber Eats experienced a data security incident that exposed Uber Eats driver data stored in the vendor's systems

In early 2022, Uber disclosed that data for approximately 820,000 Uber Eats delivery driver accounts had been exposed through a third-party vendor that provided marketing services …

Supply chain [SC]

ua-parser-js npm Package Hijack — Cryptominer and Password Stealer

2021-10-22 [vendor] ua-parser-js npm package (User-Agent string parsing library) [malware] XMRig (Monero cryptominer), jsextension (Linux), sdd.dll (Windows password stealer / DanaBot)
Vector: Attacker compromised the npm account of ua-parser-js package maintainer (faisalman) via credential theft and published three malicious versions (0.7.29, 0.8.0, 1.0.0) containing a postinstall script that deployed a cryptominer (XMRig) on Linux systems and a password-stealing trojan (DanaBot) on Windows systems; the package had approximately 22 million weekly downloads and was a dependency of thousands of packages including Facebook/Meta, Microsoft, Apple, Amazon, Google, and IBM projects

On 22 October 2021, the npm account of Faisal Salman, maintainer of the popular ua-parser-js package, was compromised. The attacker published malicious versions 0.7.29, 0.8.0, and …

Supply chain [SC]

Anthem, Humana Third-Party Breach (October 2021)

2021-10-01 [vendor] PracticeMax
Vector: Compromise of third-party service provider / vendor relationship

Third-Party Vendor Ransomware Attack Impacts Humana, Anthem Members | TechTarget. PracticeMax, a billing and IT solutions provider, experienced a ransomware attack that impacted …

Supply chain [SC]

Fullerton Health Third-Party Breach (October 2021)

2021-10-01 [vendor] Agape Connecting People
Vector: Compromise of third-party service provider / vendor relationship

Third-party data breach in Singapore hits healthcare provider. Fullerton Health says its third-party vendor, which platform facilitates appointment booking, had suffered a security …

Supply chain [SC]

Catholic Health Third-Party Breach (August 2021)

2021-08-01 [vendor] CaptureRx
Vector: Compromise of third-party service provider / vendor relationship

Catholic Health Impacted by CaptureRx Data Breach, Patients’ PHI Exposed | TechTarget. The CaptureRx data breach is impacting 17K Catholic Health patients in New York. Catholic …

Supply chain [SC]

Hospitals Third-Party Breach (July 2021)

2021-07-01 [vendor] ClearBalance
Vector: Compromise of third-party service provider / vendor relationship

ClearBalance Data Incident Impacts Over 200,000 US Patients' PII | TechTarget. A new cyberattack is impacting over 200,000 patients across the country. ClearBalance, a …

Supply chain [SC]

Hospitals Third-Party Breach (July 2021)

2021-07-01 [vendor] PracticeFirst
Vector: Compromise of third-party service provider / vendor relationship

Supply Chain Ransomware Breach Affects 1.2 Million. A supply chain ransomware attack affecting more than 1.2 million individuals is among the largest health data breaches reported …

Supply chain [SC]

Accellion FTA Zero-Day Cl0p Mass Breach — 100+ Organizations

2021-07-01 [vendor] Accellion File Transfer Appliance (FTA) [malware] DEWMODE web shell
Vector: Cl0p ransomware group exploited four zero-day vulnerabilities (CVE-2021-27101 through CVE-2021-27104) in Accellion's legacy File Transfer Appliance (FTA); the FTA was a 20-year-old product that Accellion was actively trying to migrate customers away from

See comprehensive record: data/supply-chain/2021-01_accellion-fta-clop.yaml. The Accellion FTA breach affected 100+ organizations worldwide including Reserve Bank of New Zealand, …

Supply chain [SC]

SpreadGroup Customers Third-Party Breach (July 2021)

2021-07-01 [vendor] Spreadshirt, Spreadshop, and TeamShirts
Vector: Compromise of third-party service provider / vendor relationship

DarkSide behind Guess breach. Print-on-demand vendor data compromises. Patient data phished from lender. Gambling venue operator breached.. Experts guess DarkSide behind Guess …

Supply chain [SC]

AmeriGas Third-Party Breach (June 2021)

2021-06-01 [vendor] J. J. Keller
Vector: Compromise of third-party service provider / vendor relationship

Largest US propane distributor discloses '8-second' data breach. America's largest propane provider, AmeriGas, has disclosed a data breach that lasted ephemerally but impacted 123 …

Supply chain [SC]

CVS Health Third-Party Breach (June 2021)

2021-06-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

CVS Health Faces Data Breach,1B Search Records Exposed | TechTarget. A CVS Health data breach led to over 1 billion search records being accidentally posted online, as reported by …

Supply chain [SC]

Saudi Aramco Contractor Data Breach — 1TB Exfiltrated, $50M Ransom Demand, 14,000 Employee Records

2021-06-01 [vendor] Unnamed third-party contractor (Saudi Aramco)
Vector: Compromise of a third-party contractor with access to Saudi Aramco internal data; exfiltration via the contractor's systems rather than Aramco's own network

In July 2021, a threat actor using the name "ZeroX" began advertising 1 terabyte of data stolen from Saudi Arabian Oil Company (Saudi Aramco) on a darknet forum, demanding $50 …

Supply chain [SC]

Ardagh Clients Third-Party Breach (May 2021)

2021-05-01 [vendor] Ardagh
Vector: Compromise of third-party service provider / vendor relationship

Web Application Security, Testing, & Scanning - PortSwigger. PortSwigger offers tools for web application security, testing, & scanning. Choose from a range of security tools, & …

Supply chain [SC]

Canada Post Third-Party Breach (May 2021)

2021-05-01 [vendor] CommPort Communications
Vector: Compromise of third-party service provider / vendor relationship

Canada Post hit by data breach after supplier ransomware attack. Canada Post has informed 44 of its large commercial customers that a ransomware attack on a third-party service …

Supply chain [SC]

Fujitsu ProjectWEB Breach — Japanese Government Agencies, 76,000 Email Addresses, Narita Airport Data

2021-05-01 [vendor] Fujitsu ProjectWEB
Vector: Stolen/compromised user account credentials for Fujitsu's ProjectWEB collaboration platform, enabling unauthorized access to client project workspaces

In May 2021, multiple Japanese government agencies disclosed that sensitive data had been exfiltrated via Fujitsu's ProjectWEB platform, an enterprise project information-sharing …

Supply chain [SC]

U.S. Government Third-Party Breach (May 2021)

2021-05-01 [vendor] BlueForce
Vector: Compromise of third-party service provider / vendor relationship

US defense contractor BlueForce apparently hit by ransomware | TechTarget. A Virginia-based U.S. defense contractor has apparently been hit by ransomware, according to a ransomware …

Supply chain [SC]

Celcius Third-Party Breach (April 2021)

2021-04-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Celsius Suffers Third-Party Data Breach, Customers Report Phishing Texts, Emails. The crypto lender's data leak comes almost a year to the date after a similar data leak hit …

Supply chain [SC]

Accellion FTA Zero-Day Cl0p Mass Breach — 100+ Organizations

2021-04-01 [vendor] Accellion File Transfer Appliance (FTA) [malware] DEWMODE web shell
Vector: Cl0p ransomware group exploited four zero-day vulnerabilities (CVE-2021-27101 through CVE-2021-27104) in Accellion's legacy File Transfer Appliance (FTA); the FTA was a 20-year-old product that Accellion was actively trying to migrate customers away from

See comprehensive record: data/supply-chain/2021-01_accellion-fta-clop.yaml. The Accellion FTA breach affected 100+ organizations worldwide including Reserve Bank of New Zealand, …

Supply chain [SC]

Department of Health and Human Services,UChicago, King's Daughters' Health System, OSF HealthCare, Aspirus, UChicago Medicine, and Memorial Hermann Health System. Third-Party Breach (April 2021)

2021-04-01 [vendor] MedData
Vector: Compromise of third-party service provider / vendor relationship

Patient Data from Multiple Providers Leaked in Third-Party GitHub Incident | TechTarget. Data breach notifications and a report reveal a former MedData employee uploaded troves of …

Supply chain [SC]

Ei2 Third-Party Breach (April 2021)

2021-04-01 [vendor] I-vic International
Vector: Compromise of third-party service provider / vendor relationship

Third-party security breach compromises data of Singapore job-matching service. Job-matching institute e2i says the personal details of 30,000 individuals may have been illegally …

Supply chain [SC]

Park Mobile Third-Party Breach (April 2021)

2021-04-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

ParkMobile Breach Exposes License Plate Data, Mobile Numbers of 21M Users. Someone is selling account information for 21 million customers of ParkMobile, a mobile parking app …

Supply chain [SC]

Peach Aviation, ZIPAIR Tokyo, Air Belgium, Sky Airlines, Air Transat, Vietravel, Aero K Airlines, Salam Air, FlySafair, Air India Express, Wingo Third-Party Breach (April 2021)

2021-04-01 [vendor] Radixx (subsidiary of Sabre Corporation)
Vector: Compromise of third-party service provider / vendor relationship

Malware attack on Radixx Res disrupts 20 airlines' ticket reservation systems - DataBreaches.Net. Radixx , a subsidiary of Sabre Corporation, provides an air passenger ticket …

Supply chain [SC]

Accellion FTA Zero-Day Cl0p Mass Breach — 100+ Organizations

2021-04-01 [vendor] Accellion File Transfer Appliance (FTA) [malware] DEWMODE web shell
Vector: Cl0p ransomware group exploited four zero-day vulnerabilities (CVE-2021-27101 through CVE-2021-27104) in Accellion's legacy File Transfer Appliance (FTA); the FTA was a 20-year-old product that Accellion was actively trying to migrate customers away from

See comprehensive record: data/supply-chain/2021-01_accellion-fta-clop.yaml. The Accellion FTA breach affected 100+ organizations worldwide including Reserve Bank of New Zealand, …

Supply chain [SC]

Upstox Third-Party Breach (April 2021)

2021-04-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Upstox alerts its users of data breach; funds, securities safe. On receipt of e-mails claiming unauthorized access into Upstox database, the company has appointed a cyber-security …

Supply chain [SC]

Wiener & Kennedy Third-Party Breach (April 2021)

2021-04-01 [vendor] Perkins & Co, Netgain (4th party)
Vector: Compromise of third-party service provider / vendor relationship

Wieden+Kennedy Employees Exposed to a Data Breach. This is a preview. This ad will run at the top of the page as expected when running (or previewing) on your website. …

Supply chain [SC]

Austin ISD Third-Party Breach (March 2021)

2021-03-01 [vendor] not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Austin ISD warns of possible data breach. Those who have been affected are being offered free identity monitoring. AUSTIN, Texas — Austin ISD notified parents last week after it …

Supply chain [SC]

Calviva Health Third-Party Breach (March 2021)

2021-03-01 [vendor] Health Net Community Solutions, Inc, Accellion
Vector: Compromise of third-party service provider / vendor relationship

Local health plan manager announces data breach. [](http://thebusinessjournal.com/local-health-plan-manager-announces-data-breach/#menu-location-primary). …

Supply chain [SC]

Accellion FTA Zero-Day Cl0p Mass Breach — 100+ Organizations

2021-03-01 [vendor] Accellion File Transfer Appliance (FTA) [malware] DEWMODE web shell
Vector: Cl0p ransomware group exploited four zero-day vulnerabilities (CVE-2021-27101 through CVE-2021-27104) in Accellion's legacy File Transfer Appliance (FTA); the FTA was a 20-year-old product that Accellion was actively trying to migrate customers away from

See comprehensive record: data/supply-chain/2021-01_accellion-fta-clop.yaml. The Accellion FTA breach affected 100+ organizations worldwide including Reserve Bank of New Zealand, …

Supply chain [SC]

Israeli Likud Party Third-Party Breach (March 2021)

2021-03-01 [vendor] Elector Software
Vector: Compromise of third-party service provider / vendor relationship

Personal details of all Israeli voters again leaked online, day before election. Anonymous hackers publish databases with 6.5 million names and ID numbers, including where people …

Supply chain [SC]

Poll County Schools Third-Party Breach (March 2021)

2021-03-01 [vendor] PCS Revenue Systems
Vector: Compromise of third-party service provider / vendor relationship

Data breach involving former Polk County Schools vendor could impact thousands. This issue involves a company hired by Polk Schools to collect information about students using the …

Supply chain [SC]

Accellion FTA Zero-Day Cl0p Mass Breach — 100+ Organizations

2021-03-01 [vendor] Accellion File Transfer Appliance (FTA) [malware] DEWMODE web shell
Vector: Cl0p ransomware group exploited four zero-day vulnerabilities (CVE-2021-27101 through CVE-2021-27104) in Accellion's legacy File Transfer Appliance (FTA); the FTA was a 20-year-old product that Accellion was actively trying to migrate customers away from

See comprehensive record: data/supply-chain/2021-01_accellion-fta-clop.yaml. The Accellion FTA breach affected 100+ organizations worldwide including Reserve Bank of New Zealand, …

Supply chain [SC]

Accellion FTA Zero-Day Cl0p Mass Breach — 100+ Organizations

2021-03-01 [vendor] Accellion File Transfer Appliance (FTA) [malware] DEWMODE web shell
Vector: Cl0p ransomware group exploited four zero-day vulnerabilities (CVE-2021-27101 through CVE-2021-27104) in Accellion's legacy File Transfer Appliance (FTA); the FTA was a 20-year-old product that Accellion was actively trying to migrate customers away from

See comprehensive record: data/supply-chain/2021-01_accellion-fta-clop.yaml. The Accellion FTA breach affected 100+ organizations worldwide including Reserve Bank of New Zealand, …

Supply chain [SC]

Accellion FTA Zero-Day Cl0p Mass Breach — 100+ Organizations

2021-03-01 [vendor] Accellion File Transfer Appliance (FTA) [malware] DEWMODE web shell
Vector: Cl0p ransomware group exploited four zero-day vulnerabilities (CVE-2021-27101 through CVE-2021-27104) in Accellion's legacy File Transfer Appliance (FTA); the FTA was a 20-year-old product that Accellion was actively trying to migrate customers away from

See comprehensive record: data/supply-chain/2021-01_accellion-fta-clop.yaml. The Accellion FTA breach affected 100+ organizations worldwide including Reserve Bank of New Zealand, …

Supply chain [SC]

Accellion FTA Zero-Day Cl0p Mass Breach — 100+ Organizations

2021-03-01 [vendor] Accellion File Transfer Appliance (FTA) [malware] DEWMODE web shell
Vector: Cl0p ransomware group exploited four zero-day vulnerabilities (CVE-2021-27101 through CVE-2021-27104) in Accellion's legacy File Transfer Appliance (FTA); the FTA was a 20-year-old product that Accellion was actively trying to migrate customers away from

See comprehensive record: data/supply-chain/2021-01_accellion-fta-clop.yaml. The Accellion FTA breach affected 100+ organizations worldwide including Reserve Bank of New Zealand, …

Supply chain [SC]

Air India SITA Passenger Service System Breach — 4.5 Million Passengers

2021-02-26 [vendor] SITA Passenger Service System (third-party aviation IT provider)
Vector: SITA Passenger Service System (PSS) — a third-party aviation IT infrastructure provider serving 90% of the world's airlines — was breached by an unknown attacker; the breach affected airline passenger data stored on SITA's servers; multiple airlines' passenger data was compromised through the single SITA breach

On 26 February 2021, SITA — the world's leading IT provider to the air transport industry, serving approximately 90% of international airlines — disclosed that its Passenger …

Supply chain [SC]

Singapore Airlines KrisFlyer Frequent Flyer SITA Breach — 580,000 Members

2021-02-26 [vendor] SITA Passenger Service System (third-party aviation IT)
Vector: SITA Passenger Service System (PSS) breach — the same third-party aviation IT provider breach that affected Air India; Singapore Airlines KrisFlyer member data stored on SITA's PSS servers was accessed by the attacker; the SITA breach affected multiple airlines simultaneously

Singapore Airlines disclosed on 5 March 2021 that its KrisFlyer frequent flyer programme member data had been compromised through the SITA Passenger Service System breach disclosed …

Supply chain [SC]

SITA Passenger Service System Breach — 2.1M+ Frequent Flyer Records, 11 Airlines Affected

2021-02-24 [vendor] SITA Passenger Service System (Horizon PSS)
Vector: Highly sophisticated attack on SITA's Passenger Service System (PSS) server infrastructure; exact initial intrusion method not publicly disclosed by SITA

On February 24, 2021, SITA — one of the world's largest aviation IT companies, serving approximately 90% of global airlines through its Passenger Service System (PSS) — detected …

Supply chain [SC]

CaptureRx Ransomware Breach — 1.9M Patients, 340B Healthcare Providers Across US

2021-02-06 [vendor] CaptureRx (NEC Networks) [malware] Ransomware (strain not publicly identified)
Vector: Ransomware with data exfiltration prior to encryption (double-extortion) targeting CaptureRx, a 340B pharmaceutical administration services vendor

NEC Networks LLC, doing business as CaptureRx, a San Antonio, Texas-based provider of 340B drug pricing program administrative services to healthcare organizations, suffered a …

Supply chain [SC]

Airbus, Air Caraïbes, ArcelorMittal, BT, Luxottica, Kuehne + Nagel, Ministère de la Justice français, New Zealand Police, PWC Russia, Salomon, Sanofi, and Sephora (possibly) Third-Party Breach (February 2021)

2021-02-01 [vendor] Centreon
Vector: Compromise of third-party service provider / vendor relationship

Hackers Exploit IT Monitoring Tool Centreon to Target Several French Entities. Russia-linked state-sponsored hackers Sandworm targeted IT monitoring software company Centreon in a …

Supply chain [SC]

Accellion FTA Zero-Day Cl0p Mass Breach — 100+ Organizations

2021-02-01 [vendor] Accellion File Transfer Appliance (FTA) [malware] DEWMODE web shell
Vector: Cl0p ransomware group exploited four zero-day vulnerabilities (CVE-2021-27101 through CVE-2021-27104) in Accellion's legacy File Transfer Appliance (FTA); the FTA was a 20-year-old product that Accellion was actively trying to migrate customers away from

See comprehensive record: data/supply-chain/2021-01_accellion-fta-clop.yaml. The Accellion FTA breach affected 100+ organizations worldwide including Reserve Bank of New Zealand, …

Supply chain [SC]

Accellion FTA Zero-Day Cl0p Mass Breach — 100+ Organizations

2021-02-01 [vendor] Accellion File Transfer Appliance (FTA) [malware] DEWMODE web shell
Vector: Cl0p ransomware group exploited four zero-day vulnerabilities (CVE-2021-27101 through CVE-2021-27104) in Accellion's legacy File Transfer Appliance (FTA); the FTA was a 20-year-old product that Accellion was actively trying to migrate customers away from

See comprehensive record: data/supply-chain/2021-01_accellion-fta-clop.yaml. The Accellion FTA breach affected 100+ organizations worldwide including Reserve Bank of New Zealand, …

Supply chain [SC]

Codecov Bash Uploader Supply Chain Attack — CI/CD Credential Exfiltration

2021-01-31 [vendor] Codecov Bash Uploader (codecov.io CI/CD code coverage reporting tool)
Vector: Attacker exploited a flaw in Codecov's Docker image creation process to extract credentials from Codecov's Google Cloud Storage bucket; used these credentials to modify the bash uploader script (bash.codecov.io/bash) — distributed to CI/CD pipelines globally — to exfiltrate environment variables including secrets, API tokens, and credentials to an attacker-controlled server (opcode.io)

Between 31 January and 1 April 2021, attackers silently modified Codecov's popular bash uploader script, which thousands of CI/CD pipelines used to upload code coverage reports. …

Supply chain [SC]

SonicWall SMA 100 Zero-Day Exploitation (January 2021)

2021-01-22 [vendor] SonicWall Secure Mobile Access (SMA) 100 Series [cve] CVE-2021-20016
Vector: Zero-day SQL injection vulnerability in SonicWall SMA 100 series VPN appliances exploited for credential theft and remote code execution

In late January 2021, SonicWall disclosed that its own internal systems and Secure Mobile Access (SMA) 100 series VPN appliances were targeted by sophisticated threat actors …

Supply chain

Nevada Restaurant Services (Dotty's) Malware Breach (2021)

2021-01-16 [vendor] Nevada Restaurant Services / Dotty's [malware] unspecified malware
Vector: Malware infection enabling unauthorized data exfiltration from internal systems

Nevada Restaurant Services (NRS), the parent company of slot machine parlor chain Dotty's, disclosed a data breach in September 2021 after identifying the presence of malware on …

Supply chain [SC]

ASIC Accellion FTA Breach — Australian Securities Regulator File Transfer Compromise

2021-01-15 [vendor] Accellion File Transfer Appliance (FTA) used by ASIC [malware] Cl0p / DEWMODE web shell [cve] CVE-2021-27101 +3
Vector: Cl0p ransomware group exploited zero-day vulnerabilities in Accellion File Transfer Appliance (FTA) that ASIC used to receive and send documents; the vulnerability allowed unauthorized access to file transfer systems and exfiltration of files that had been submitted to ASIC

In January 2021, the Australian Securities and Investments Commission (ASIC) — Australia's corporate, markets, and financial services regulator — disclosed that its Accellion File …

Supply chain [SC]

Bonobos Third-Party Breach (January 2021)

2021-01-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Data breach at Bonobos hits up to 7 million: What to do [updated]. When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works. Here at …

Supply chain [SC]

OmniTRAX Third-Party Breach (January 2021)

2021-01-01 [vendor] Broe Group
Vector: Compromise of third-party service provider / vendor relationship

Ransomware Attack Hits Short Line Rail Operator OmniTRAX. Colorado-based short line rail operator and logistics provider OmniTRAX was hit by a recent ransomware attack and data …

Supply chain [SC]

Mandiant / CISA AA21-055A / BleepingComputer / Tenable

2020-12-25 [vendor] Accellion File Transfer Appliance (FTA) [malware] DEWMODE webshell / FINTEAM [cve] CVE-2021-27101 +3
Vector: CWE-89: SQL Injection (CVE-2021-27101 HOST header injection) leading to DEWMODE webshell installation

FIN11 / UNC2546 (linked to Cl0p/TA505) exploited four zero-days in legacy 20-year-old Accellion FTA product starting Dec 25 2020. Used DEWMODE webshell to exfiltrate data. ~100 of …

Supply chain [SC]

Accellion FTA Breach — Reserve Bank of New Zealand and ASIC (January 2021)

2020-12-23 [vendor] Accellion File Transfer Appliance (FTA) [malware] DEWMODE web shell [cve] CVE-2021-27101 +3
Vector: SQL injection and OS command injection zero-days in Accellion File Transfer Appliance (FTA) legacy software

The Accellion FTA (File Transfer Appliance) breach was one of the most consequential supply-chain attacks of early 2021, affecting dozens of major organisations worldwide through a …

Supply chain [SC]

Microsoft Third-Party Breach (December 2020)

2020-12-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Russian hackers compromised Microsoft cloud customers through third party, putting emails and other data at risk. Outside Microsoft’s French headquarters in Issy-Les-Moulineaux, …

Supply chain [SC]

Now:Pensions Third-Party Breach (December 2020)

2020-12-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Data breach hits 30,000 signed up to workplace pensions provider. Fraud worries as UK company Now:Pensions says ‘third-party contractor’ posted personal details of clients to …

Supply chain [SC]

WildWorks Third-Party Breach (November 2020)

2020-11-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Animal Jam Hacked, 46M Records Roam the Dark Web. Animal Jam, just the latest in a string of attacks on gaming apps, has adopted a transparent communications strategy after stolen …

Supply chain

Lazada RedMart Singapore Database Breach (October 2020)

2020-10-29 [vendor] Not disclosed
Vector: Unauthorized access to an unsecured legacy MongoDB database for the old RedMart app and website; data predated March 2019

Lazada, the Alibaba-owned Southeast Asian e-commerce platform, disclosed a data breach affecting approximately 1.1 million customers of its Singapore-based grocery delivery service …

Supply chain [SC]

JM Bullion Third-Party Breach (October 2020)

2020-10-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Precious Metal Trader JM Bullion Acknowledges Breach. In a notification letter filed to the Montana Department of Justice, precious metal trader JM Bullion has revealed that an …

Supply chain [SC]

Luxottica Breach Affecting LensCrafters, EyeMed, Target Optical (August–September 2020)

2020-08-05 [vendor] Luxottica [malware] Nefilim ransomware
Vector: Hacking of Luxottica's web-based appointment scheduling application; followed by separate Nefilim ransomware attack on September 18, 2020

Luxottica, the Italian eyewear conglomerate and parent company of EyeMed Vision Care, LensCrafters, Target Optical, and Pearle Vision, suffered two separate but related security …

Supply chain [SC]

Jack Daniel's Third-Party Breach (August 2020)

2020-08-01 [vendor] Brown-Forman
Vector: Compromise of third-party service provider / vendor relationship

Jack Daniel’s-Maker Suffers REvil Ransomware Breach. Attackers claim to have 1TB of stolen data in their possession. US wine and spirits giant Brown-Forman has become the latest …

Supply chain [SC]

Rochester YMCA Third-Party Breach (August 2020)

2020-08-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Data Breach May Have Affected Some Rochester YMCA Accounts. Donors of the Rochester YMCA have been notified of a data breach that may have affected their personal information. …

Supply chain [SC]

Citrix Third-Party Breach (July 2020)

2020-07-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Citrix data exposed in third-party breach | TechTarget. Citrix Tuesday published a blog confirming that a third-party organization is investigating a possible data breach after a …

Supply chain [SC]

Promo.com Third-Party Breach (July 2020)

2020-07-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Web Application Security, Testing, & Scanning - PortSwigger. PortSwigger offers tools for web application security, testing, & scanning. Choose from a range of security tools, & …

Supply chain [SC]

Dave Banking App via Waydev OAuth Token Theft (July 2020)

2020-06-10 [vendor] Waydev (git analytics third-party vendor)
Vector: Blind SQL injection in Waydev analytics platform used to steal GitHub and GitLab OAuth tokens, enabling downstream access to Dave user database

In July 2020, the personal data of approximately 7.5 million users of Dave — a US-based neobank and personal finance app — was compromised and subsequently leaked on a public …

Supply chain [SC]

Keepnet Third-Party Breach (June 2020)

2020-06-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Keepnet Labs confirms contractor exposed 'data breach database' of 5 billion records. Keepnet Labs has confirmed that a contractor temporarily exposed a database containing five …

Supply chain [SC]

MU Health Third-Party Breach (June 2020)

2020-06-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

MU Health reports data breach. University of Missouri Health Care said Thursday that it has notified patients affected by a September data breach. The organization said in a news …

Supply chain [SC]

Police Departments Third-Party Breach (June 2020)

2020-06-01 [vendor] NetSentiel
Vector: Compromise of third-party service provider / vendor relationship

‘BlueLeaks’ Exposes Files from Hundreds of Police Departments. Hundreds of thousands of potentially sensitive files from police departments across the United States were leaked …

Supply chain [SC]

Bank of America Third-Party Breach (May 2020)

2020-05-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Bank of America Responds to Breach. Bank of America blames a suspected breach of credit card data on an unidentified third party. What happened, and what can other institutions do …

Supply chain [SC]

MNS' Healthcare Clients Third-Party Breach (May 2020)

2020-05-01 [vendor] Management and Network Services – MNS
Vector: Compromise of third-party service provider / vendor relationship

Management and Network Services Notifies 30,132 Patients About PHI Breach. Management and Network Services has discovered multiple email accounts have been compromised. The PHI of …

Supply chain [SC]

TrueCaller Third-Party Breach (May 2020)

2020-05-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

TrueCaller Data of 4.75 Cr Indians for Sale On Dark Web: Report. Online intelligence firm Cyble flagged that a cybercriminal was selling Truecaller records of 4.75 crore Indians on …

Supply chain [SC]

Chubb Third-Party Breach (March 2020)

2020-03-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Cyber insurer Chubb had data stolen in Maze ransomware attack. Chubb, a major cybersecurity insurance provider for businesses hit by data breaches, has itself become a target of a …

Supply chain [SC]

General Electric Third-Party Breach (March 2020)

2020-03-01 [vendor] Canon Business Services
Vector: Compromise of third-party service provider / vendor relationship

Third-party data breach exposes GE employees' personal information. Past and present employees of GE are learning that their sensitive information has been exposed by a data breach …

Supply chain [SC]

Radio.com Third-Party Breach (March 2020)

2020-03-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Radio.com users affected in data breach. Entercom, the second-largest radio company in the United States, has announced that it suffered a cybersecurity incident that affected …

Supply chain [SC]

T-Mobile Third-Party Breach (March 2020)

2020-03-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

T-Mobile warns customers about a recent data breach. T-Mobile this week notified customers about a data breach. According to the alert, a malicious third-party gained access to …

Supply chain [SC]

Blackbaud CRM Ransomware/Data Theft (Nonprofits, Universities, Healthcare)

2020-02-07 [vendor] Blackbaud cloud CRM platform
Vector: Ransomware attackers infiltrated Blackbaud's self-hosted cloud environment; before deploying ransomware, exfiltrated a copy of a subset of data from its cloud backup environment; Blackbaud paid the ransom in exchange for assurance the data was deleted

Blackbaud, the world's largest provider of cloud software for nonprofits, universities, healthcare organizations, and foundations, disclosed in July 2020 that it had suffered a …

Supply chain [SC]

Blackbaud Ransomware Attack Affecting Universities Globally (May–July 2020)

2020-02-07 [vendor] Blackbaud (cloud CRM and fundraising software) [malware] ransomware
Vector: Ransomware attack on Blackbaud cloud CRM infrastructure with prior data exfiltration; ransom paid to obtain deletion assurances

In May 2020, Blackbaud — one of the world's largest providers of cloud-based CRM and fundraising software for universities, hospitals, and nonprofits — suffered a ransomware attack …

Supply chain [SC]

Carson City Third-Party Breach (February 2020)

2020-02-01 [vendor] Click2Gov
Vector: Compromise of third-party service provider / vendor relationship

Hackers compromise financial information for Carson City residents who pay water bill online - Carson Now. According to a letter sent out to a group of residents who pay their …

Supply chain [SC]

Nedbank Third-Party Breach (February 2020)

2020-02-01 [vendor] Computer Facilities (Pty) Ltd
Vector: Compromise of third-party service provider / vendor relationship

Nedbank says 1.7 million customers impacted by breach at third-party provider. Hacker(s) believed to have exploited a vulnerability to breach Nedbank's marketing contractor. …

Supply chain [SC]

Rutters Store Third-Party Breach (February 2020)

2020-02-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Rutters store chain reveals malware attacked its POS system. Convenience store company warns that malware collected payment card details as they were being processed. Convenience …

Supply chain [SC]

Amazon Insider Data Leak (January 2020)

2020-01-10 [vendor] Amazon
Vector: Malicious insider / rogue employee data exfiltration to unauthorized third party

In January 2020, Amazon discovered that one or more employees had shared customer email addresses and phone numbers with an unauthorized third party in violation of company policy. …

Supply chain [SC]

Regus Third-Party Breach (January 2020)

2020-01-01 [vendor] Applause
Vector: Compromise of third-party service provider / vendor relationship

WeWork rival Regus in massive employee data breach. This feature is available for registered users. Please register or log in to continue. …

Supply chain [SC]

City of Sioux Third-Party Breach (December 2019)

2019-12-01 [vendor] Click2Gov
Vector: Compromise of third-party service provider / vendor relationship

Data security breach impacts City of Sioux City customers. SIOUX CITY -- A data security breach has potentially impacted more than 3,500 City of Sioux City customer utility and …

Supply chain [SC]

Florida Blue Third-Party Breach (November 2019)

2019-11-01 [vendor] Magellan Health Inc
Vector: Compromise of third-party service provider / vendor relationship

Data breach put thousands of Florida Blue members' personal information at risk. A data breach at Magellan Health Inc. has put the personal information of Florida Blue members at …

Supply chain [SC]

Macy's Third-Party Breach (November 2019)

2019-11-01 [vendor] not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Macy’s suffers online Magecart card-skimming attack, data breach. The department store detected malicious code in its online payment portal. Macy's has announced a data breach …

Supply chain [SC]

CenturyLink Third-Party Breach (October 2019)

2019-10-01 [vendor] not disclosed
Vector: Compromise of third-party service provider / vendor relationship

CenturyLink customers may have had data exposed in 'security incident'. The company says the incident involving a third party vendor may have exposed contact information. GOLDEN …

Supply chain [SC]

UniCredit Third-Party Breach (October 2019)

2019-10-01 [vendor] not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Our pick of the top fintech news stories this week includes Revolut, Coinbase, Bolt, FundApps, and more. Copyright © 2026 Informa PLC. Informa PLC is registered in England and …

Supply chain [SC]

Active Network Blue Bear Platform — Web Skimming Attack on School Stores (2019–2020)

2019-10-01 [vendor] Active Network (Blue Bear platform) [malware] JavaScript web skimmer
Vector: Web skimming (Magecart-style) attack — malicious JavaScript injected into Blue Bear school e-commerce platform to harvest payment card data at point of entry

Between October 1 and November 13, 2019, unknown attackers gained unauthorized access to Blue Bear, Active Network's web-based school accounting and online store management …

Supply chain [SC]

Malinda Air Third-Party Breach (September 2019)

2019-09-01 [vendor] not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Malinda Air locks down publicly exposed servers. Indonesian budget airline Malindo Air reported on September 19 it had locked down the formerly publicly exposed servers that had …

Supply chain [SC]

Yves Rocher Third-Party Breach (September 2019)

2019-09-01 [vendor] Aliznet
Vector: Compromise of third-party service provider / vendor relationship

Cosmetics Giant Yves Rocher Caught in Data Leak Impacting Millions of Customers. International cosmetics brand Yves Rocher found itself caught in a third-party data exposure …

Supply chain [SC]

Mastercard Priceless Specials Loyalty Program Breach

2019-08-19 [vendor] Priceless Specials loyalty platform (third-party operated)
Vector: Third-party loyalty program operator compromise; data exfiltrated and posted publicly online

On August 19, 2019, data belonging to approximately 90,000 members of Mastercard's Priceless Specials loyalty program was posted publicly on the internet, triggering Mastercard to …

Supply chain [SC]

DeKalb School District 428, Wilmette Public Schools District 39,The School District of Clayton,Brighton, Brockport, East Irondequoit, Fairport, East Rochester, Greece, Pittsford, Rochester, Spencerport, Victor, Webster and West Irondequoit school districts Third-Party Breach (August 2019)

2019-08-01 [vendor] Pearson Clinical Assessment (AIMSweb)
Vector: Compromise of third-party service provider / vendor relationship

Daily Chronicle. News • Sports • eNewspaper • Obituaries • Election • The Scene • 175 Years. …

Supply chain [SC]

Volkswagen/Audi Shift Digital Breach — 3.3M Customers, Unsecured Cloud Data 2019–2021

2019-08-01 [vendor] Shift Digital (digital marketing vendor for Volkswagen Group of America)
Vector: Misconfigured cloud storage — Shift Digital left an unsecured dataset containing VW/Audi customer data exposed on the internet between August 2019 and May 2021

Volkswagen Group of America and Audi of America disclosed in June 2021 that approximately 3.3 million customers and prospective buyers had their personal data exposed due to an …

Supply chain

Dickey's Barbecue Pit POS Malware Breach — 3M Cards on Joker's Stash (2019–2020)

2019-07-01 [vendor] Not disclosed [malware] POS memory-scraping malware (specific family not disclosed)
Vector: Point-of-sale (POS) malware installed on in-store payment systems; likely facilitated by remote access compromise or supply chain intrusion into POS provider

Dickey's Barbecue Pit, a Dallas-based smoked-meat restaurant chain with approximately 469 locations across the United States, suffered a prolonged point-of-sale (POS) malware …

Supply chain [SC]

Mitsubishi Electric Breach — Tick APT / Trend Micro OfficeScan Zero-Day (2019–2020)

2019-06-28 [vendor] Trend Micro OfficeScan (via China-based affiliated company) [cve] CVE-2019-18187
Vector: Exploitation of zero-day vulnerability (CVE-2019-18187) in Trend Micro OfficeScan antivirus via compromised China-based affiliate, enabling lateral movement to Japan headquarters

On June 28, 2019, threat actors — widely attributed to the Chinese state-sponsored APT group known as Tick (also tracked as Bronze Butler and associated with APT40) — breached …

Supply chain [SC]

Komodo Third-Party Breach (June 2019)

2019-06-01 [vendor] not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Latest Blockchain News, BSV Insights, and AI Web3 Trends from CoinGeek. A serious vulnerability has been discovered in a cryptocurrency wallet app, putting millions of dollars’ …

Supply chain [SC]

Instagram Influencer Data Exposed via Chtrbox Unsecured Database

2019-05-14 [vendor] Chtrbox (Mumbai-based Instagram influencer marketing platform)
Vector: Misconfigured cloud database (unauthenticated instance, no password protection)

In May 2019, security researcher Anurag Sen discovered a large, unsecured database containing scraped Instagram profile data for approximately 49 million users, which he traced to …

Supply chain [SC]

4,600 websites Third-Party Breach (May 2019)

2019-05-01 [vendor] Picreel and Alpaca Forms
Vector: Compromise of third-party service provider / vendor relationship

Hackers are collecting payment details, user passwords from thousands of sites. Servers of at least seven companies compromised to deliver malicious code to thousands of sites. …

Supply chain [SC]

Forbes Third-Party Breach (May 2019)

2019-05-01 [vendor] not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Forbes Becomes Latest Victim of Magecart Payment Card Skimmer. The web skimming script was recently found stealing payment data on the websites of Forbes Magazine as well as seven …

Supply chain [SC]

Truecaller Third-Party Breach (May 2019)

2019-05-01 [vendor] not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Truecaller Users’ Phone Numbers & Email IDs For Sale on Dark Web. Truecaller Number Search App: The caller ID company with more than millions of users in India caters to mobile …

Supply chain [SC]

U.S. Customs and Border Protection via Perceptics Subcontractor Breach

2019-05-01 [vendor] Perceptics LLC [malware] ransomware (unnamed, targeted subcontractor network)
Vector: Unauthorized data transfer to subcontractor network followed by ransomware attack on subcontractor

In May–June 2019, U.S. Customs and Border Protection (CBP) experienced a major privacy and cybersecurity incident involving the unauthorized exposure of traveler facial recognition …

Supply chain [SC]

UNIQLO Third-Party Breach (May 2019)

2019-05-01 [vendor] not
Vector: Compromise of third-party service provider / vendor relationship

Cyber-attack affects over 460,000 online store accounts. The compromised information included, customer name, address, phone number, email address, gender, date of birth, purchase …

Supply chain [SC]

Webstorage users Third-Party Breach (May 2019)

2019-05-01 [vendor] ASUS Webstorage
Vector: Compromise of third-party service provider / vendor relationship

ASUS WebStorage abused to spy on users at the router level. Vulnerable software is potentially facilitating surveillance and data theft. The ASUS WebStorage system is being …

Supply chain [SC]

Cable ONE Employee Email Account Breach

2019-05-01 [vendor] not disclosed (third-party email or HR vendor)
Vector: Unauthorized access to employee email accounts via compromised third-party vendor; approximately 14 accounts accessed

In May 2019, Cable ONE (now Sparklight), a US cable television and internet provider headquartered in Phoenix, Arizona, discovered that an unauthorized individual had gained access …

Supply chain [SC]

PrismRBS / Mirrorthief Magecart Skimming Attack — 201 Campus Stores, 176+ Colleges (April 2019)

2019-04-14 [vendor] PrismRBS (PrismWeb e-commerce platform) [malware] Mirrorthief JavaScript card skimmer
Vector: Magecart-style JavaScript skimmer injected into shared e-commerce library of PrismWeb platform by threat actor Mirrorthief; affected all online stores built on the platform

PrismRBS is a subsidiary of Nebraska Book Company that operates PrismWeb, a white-label e-commerce platform specifically designed for college and university campus bookstores. In …

Supply chain [SC]

Westpac Bank PayID Enumeration Attack

2019-04-07 [vendor] NPP Australia PayID platform
Vector: API enumeration / credential abuse against PayID lookup service

In June 2019, Westpac Bank disclosed that attackers had exploited its PayID lookup service to harvest the names and phone numbers of approximately 98,000 Australian banking …

Supply chain [SC]

China Railway Third-Party Breach (February 2019)

2019-02-01 [vendor] not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Hacking, gone off the rails: Holiday travelers react to data breach · TechNode. We went to Beijing’s busiest train stations to ask travelers about the recent ticket-platform …

Data leak [SC]

Medibank Private 2019 Unauthorised Third-Party Access — Pre-2022 Breach

2019-02-01 [vendor] Medibank Private third-party vendor systems
Vector: Unauthorised access was obtained to customer data stored in systems managed by a third-party vendor providing services to Medibank Private; the vendor's systems were accessed without authorisation

In early 2019, Medibank Private experienced an earlier, smaller breach via a third-party vendor that accessed customer data without authorisation. This breach predated the much …

Supply chain [SC]

Amadeus Flight Booking System Vulnerability (January 2019)

2019-01-15 [vendor] Amadeus
Vector: Insecure direct object reference (IDOR) in web-based booking portal allowing unauthenticated enumeration of passenger name records (PNRs)

In January 2019, security researcher Noam Rotem discovered a critical vulnerability in the Amadeus Global Distribution System (GDS) that exposed passenger reservation data for …

Supply chain [SC]

Ascension Third-Party Breach (January 2019)

2019-01-01 [vendor] OpticsML
Vector: Compromise of third-party service provider / vendor relationship

Millions of bank loan and mortgage documents have leaked online | TechCrunch. A trove of more than 24 million financial and banking documents, representing tens of thousands of …

Supply chain [SC]

Hanover County Third-Party Breach (January 2019)

2019-01-01 [vendor] Click2Gov
Vector: Compromise of third-party service provider / vendor relationship

Custom404 • Hanover County, VA • CivicEngage. This website is AudioEye enabled and is being optimized for accessibility. To open the AudioEye Toolbar, press "shift + =". Some …

Supply chain [SC]

Humana Third-Party Breach (January 2019)

2019-01-01 [vendor] LCP Corp.
Vector: Compromise of third-party service provider / vendor relationship

Humana has notified customers of a third-party security incident that might have exposed some of their personal information. According to a breach notification letter obtained by …

Supply chain [SC]

LocalBitcoins Third-Party Breach (January 2019)

2019-01-01 [vendor] not disclosed
Vector: Compromise of third-party service provider / vendor relationship

LocalBitcoins blames security breach on forum 'third-party software'. Hackers appears to have stolen $28,200 from users' accounts after phishing login credentials and 2FA one-time …

Supply chain [SC]

ASUS Live Update ShadowHammer Supply Chain Attack — Lazarus Group / OPERATION ShadowHammer

2019-01-01 [vendor] ASUS Live Update Utility (ASUS pre-installed automatic update tool) [malware] ShadowHammer backdoor
Vector: Attackers (assessed as Lazarus Group / BARIUM) compromised ASUS's software signing infrastructure and injected malicious code into the legitimate ASUS Live Update Utility; the trojanized utility was signed with genuine ASUS digital certificates and distributed via ASUS's official update servers to approximately 1 million ASUS laptop and desktop computers worldwide

Between June 2018 and November 2018 (disclosed March 2019), attackers compromised ASUS's software build and signing infrastructure to inject a backdoor into the ASUS Live Update …

Supply chain [SC]

PHP PEAR Package Manager Supply Chain Compromise (January 2019)

2018-12-20 [vendor] PHP PEAR [malware] Perl reverse shell backdoor
Vector: Compromise of open-source package repository web server; malicious backdoor injected into official go-pear.phar installer distributed via pear.php.net

In January 2019, the PHP PEAR (PHP Extension and Application Repository) team announced that the official pear.php.net web server had been compromised by an unknown attacker who …

Supply chain [SC]

Redwood Eye Center Third-Party Breach (December 2018)

2018-12-01 [vendor] IT Lighthouse
Vector: Compromise of third-party service provider / vendor relationship

Microsoft Word - Redwood-AG Notification - California 4848-2006-9506 v.1. > ARIZONA •CALIFORNIA •COLORADO •CONNECTICUT •FLORIDA •GEORGIA •ILLINOIS •INDIANA •KANSAS •KENTUCKY …

Supply chain [SC]

Easy Programming Language (EPL) Supply Chain Attack — Taobao, Alipay, Baidu Cloud (2018)

2018-12-01 [vendor] Easy Programming Language (EPL / EasyLanguage) — Chinese programming software [malware] Credential-stealing trojan targeting Taobao, Alipay, Baidu Cloud, JD.com, NetEase 163, QQ, AliWangWang; ransomware component demanding WeChat Pay payment; signed with certificate stolen from Tencent Technologies
Vector: Trojanized Easy Programming Language (EPL/EasyLanguage) compiler/IDE distributed to Chinese developers; malicious code injected into the EPL software build environment propagated to applications compiled with it, targeting Chinese platform credentials and deploying ransomware

In late November and early December 2018, a sophisticated supply chain attack targeting Chinese internet users emerged, exploiting Easy Programming Language (EPL, also known as …

Supply chain [SC]

Gate.io / StatCounter Supply Chain Attack (2018)

2018-11-03 [vendor] StatCounter (web analytics provider) [malware] Custom JavaScript Bitcoin address-replacement skimmer
Vector: Compromise of StatCounter's web analytics platform; attackers injected malicious JavaScript into the StatCounter tracking script (counter.js), which silently replaced Bitcoin withdrawal destination addresses in real time on Gate.io's withdrawal page

On November 3, 2018, attackers compromised the StatCounter web analytics platform — used by hundreds of thousands of websites worldwide — and modified the StatCounter JavaScript …

Supply chain [SC]

BitPay Third-Party Breach (November 2018)

2018-11-01 [vendor] Right9ctrl
Vector: Compromise of third-party service provider / vendor relationship

Sophos News - The Sophos Blog. .svg?width=185&quality=80&format=auto&cache=true&immutable=true&cache-control=max-age%3D31536000). Sophos Insights LLM AI Exploit vulnerability …

Supply chain [SC]

Ontario Cannabis Store / Canada Post Data Breach (2018)

2018-11-01 [vendor] Canada Post
Vector: Unauthorized access to Canada Post's online parcel delivery tracking tool by an external actor, exposing shipment metadata for Ontario Cannabis Store customer orders

Shortly after the Ontario Cannabis Store (OCS) launched online sales following the legalization of recreational cannabis in Canada on October 17, 2018, a data breach was disclosed …

Supply chain [SC]

Image-I-Nation Technologies Supply Chain Breach Affecting Credit Bureau Customers (2018–2019)

2018-11-01 [vendor] Image-I-Nation Technologies
Vector: Network intrusion at third-party hosting and background screening software provider shared by Equifax, Experian, and TransUnion

Image-I-Nation Technologies, Inc. is a technology and hosting company that provides background screening software and data services to consumer reporting agencies (CRAs). In late …

Supply chain [SC]

Nordstrom Employee Data Breach via Contractor (2018)

2018-10-09 [vendor] Unnamed contractor (vendor identity not publicly disclosed)
Vector: Insider mishandling of employee data by a contract worker with authorized system access; unauthorized exfiltration or exposure of HR and payroll data

In October 2018, Nordstrom discovered that a contract worker had improperly handled employee personal data, resulting in the potential exposure of sensitive HR and payroll …

Supply chain [SC]

VestaCP Third-Party Breach (October 2018)

2018-10-01 [vendor] not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Vesta control panel servers infected with DDoS malware after supply chain attack. An open-source hosting panel software provider, Vesta Control Panel (VestaCP), has admitted that …

Supply chain [SC]

UK Conservative Party conference app breach via CrowdComms (September 2018)

2018-09-30 [vendor] CrowdComms conference app
Vector: Missing authentication vulnerability in a conference app built by third-party provider CrowdComms — the app allowed any user to log in as any other attendee using only an email address, with no password required, exposing profile data including personal mobile phone numbers for hundreds of MPs, ministers, journalists, and conference delegates

On September 30, 2018, during the UK Conservative Party's annual conference in Birmingham, a serious security vulnerability in the official conference mobile application was …

Supply chain [SC]

Facebook "View As" access token breach affects 50 million accounts (September 2018)

2018-09-25 [vendor] Facebook Login / Facebook platform
Vector: Exploitation of a chain of three software bugs in the Facebook "View As" privacy feature — the interaction of a misconfigured birthday video composer, a flawed video uploader that incorrectly generated access tokens with mobile app permissions, and a logic error that generated tokens for the viewed user rather than the viewer allowed attackers to harvest OAuth access tokens for approximately 50 million accounts without knowing account passwords

On the afternoon of September 25, 2018, Facebook's engineering team discovered an active attack exploiting a critical vulnerability in the platform's "View As" feature — a privacy …

Supply chain [SC]

Atrium Health / AccuDoc Solutions Data Breach (2018)

2018-09-22 [vendor] AccuDoc Solutions Inc.
Vector: Exploitation of security vulnerability at AccuDoc Solutions' third-party hosting vendor, enabling unauthorized access to AccuDoc databases containing Atrium Health patient billing data

Atrium Health, a major Charlotte, North Carolina hospital network, suffered a significant data breach affecting 2,650,000 patients through its billing services vendor AccuDoc …

Supply chain [SC]

event-stream npm Package Malware — Targeting Copay Bitcoin Wallet

2018-09-09 [vendor] event-stream npm package (Node.js event streaming utility) [malware] flatmap-stream (malicious dependency with obfuscated payload)
Vector: Attacker (right9ctrl) socially engineered the original event-stream package maintainer (dominictarr) into transferring ownership of the npm package; then published a new version that included a malicious dependency (flatmap-stream) containing obfuscated code specifically targeting the Copay bitcoin wallet application by attempting to steal private keys and transaction data from users with wallets containing more than 100 BTC

In September 2018, an unknown attacker using the account 'right9ctrl' approached the original maintainer of the popular Node.js npm package 'event-stream' (dominictarr) and …

Supply chain [SC]

Foosackly Third-Party Breach (September 2018)

2018-09-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Foosackly's reports payment-card data breach. Mobile-based chicken-finger chain Foosackly's is warning customers of a data breach in its payment system. According to information …

Supply chain [SC]

Perth Mint Depository Online data breach via third-party IT provider (September 2018)

2018-09-01 [vendor] Not disclosed (third-party IT provider hosting Depository Online database)
Vector: Compromise of an unnamed third-party IT provider that hosted an older 2016 database of Perth Mint Depository Online customer records — the Perth Mint's own internal systems were not directly breached; attackers targeted the external provider's infrastructure to obtain the hosted dataset

In September 2018, The Perth Mint — the government-owned precious metals enterprise operated by the Government of Western Australia — disclosed a data breach affecting customers of …

Supply chain [SC]

Wolverine Solutions Group Ransomware Breach — 700+ Healthcare Clients, 1.2M Patients (2018–2019)

2018-09-01 [vendor] Wolverine Solutions Group [malware] Ransomware (variant not publicly identified)
Vector: Ransomware infection at Wolverine Solutions Group; attackers encrypted company records and disrupted operations, exposing patient data held on behalf of Michigan healthcare clients

Wolverine Solutions Group (WSG) is a Detroit, Michigan-based company that provides mailing, printing, and administrative services to hospitals and healthcare organisations — …

Supply chain

Air Canada mobile app data breach (August 2018)

2018-08-22 [vendor] Air Canada mobile app
Vector: Credential stuffing attack against the Air Canada mobile app — attackers used email/password combinations from prior data breaches to systematically attempt logins against the app's authentication endpoint, successfully accessing approximately 20,000 of the 1.7 million registered accounts between August 22–24, 2018

Between August 22 and 24, 2018, Air Canada detected unusual login behaviour on its smartphone mobile application and moved quickly to lock all 1.7 million app user accounts as a …

Supply chain [SC]

British Airways Magecart payment card skimming attack (August–September 2018)

2018-08-21 [vendor] British Airways website / booking platform [malware] Magecart web skimmer
Vector: Magecart web-skimmer attack — attackers initially accessed British Airways' network via stolen credentials belonging to a third-party supplier, moved laterally through a Citrix-based remote access system, then injected 22 lines of malicious JavaScript into a modified Modernizr library loaded from the BA baggage claim information page; the skimmer exfiltrated payment card data in real-time to an attacker-controlled server in Romania during the booking checkout flow

The British Airways Magecart breach of 2018 is one of the most technically documented payment card skimming attacks on record and led to a landmark GDPR enforcement action. The …

Supply chain [SC]

BevMo / NCR Corp. E-Commerce Payment Breach (2018)

2018-08-02 [vendor] NCR Corp. [malware] JavaScript payment card skimmer (Magecart-style)
Vector: Magecart-style JavaScript skimmer injected into BevMo's e-commerce checkout page via compromise of NCR Corp.'s managed website platform; malicious code siphoned payment card data at point of entry in real time

BevMo, a California-based alcohol retail chain, disclosed in late 2018 that its e-commerce website had been compromised by a payment card skimming attack affecting 14,579 …

Supply chain [SC]

Fiserv Event Manager vulnerability exposes customer data at hundreds of banks (August 2018)

2018-08-01 [vendor] Fiserv Event Manager
Vector: Insecure direct object reference (IDOR) vulnerability in Fiserv's Event Manager messaging platform — editing a single digit in a bank website URL parameter allowed any authenticated user to view other customers' account alert data, including email addresses, phone numbers, and partial account numbers

In August 2018, KrebsOnSecurity reported a significant security flaw in Fiserv's web banking platform that exposed personal and financial details of customers at hundreds of …

Supply chain [SC]

Mention Third-Party Breach (August 2018)

2018-08-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Media monitoring app Mention suffers third-party data breach. Web and social media monitoring app Mention has revealed that a third-party provider has been hit by a data breach. …

Supply chain [SC]

AMCA (American Medical Collection Agency) Third-Party Breach — Quest Diagnostics, LabCorp, 20M Patients

2018-08-01 [vendor] AMCA web payment portal
Vector: Attacker compromised AMCA's web payment portal via unknown initial access vector; malicious code siphoned payment card data and personal information over an eight-month period before detection; AMCA was a third-party billing collections vendor for multiple major healthcare laboratories

American Medical Collection Agency (AMCA), a major third-party billing and collections vendor for US healthcare laboratories, suffered a long-running breach of its web payment …

Supply chain [SC]

Managed Health Services of Indiana / LCP Transportation Phishing Breach (2018)

2018-07-30 [vendor] LCP Transportation (LCP Corp.)
Vector: Phishing attack against LCP Transportation employees who surrendered email credentials; attackers gained remote access to employee email accounts containing Medicaid member PHI between July 30 and September 7, 2018

Managed Health Services of Indiana (MHS), which administers Indiana's Hoosier Healthwise and Hoosier Care Connect Medicaid managed care programs, disclosed in December 2018 that …

Supply chain [SC]

US Department of Defense travel records breach via unnamed contractor (October 2018)

2018-07-01 [vendor] Not disclosed (DoD travel management contractor)
Vector: Intrusion into an unnamed commercial travel management contractor's systems that processed and stored travel records for DoD personnel — the contractor's network was compromised, exposing travel itinerary data and associated payment card information for approximately 30,000 military and civilian DoD employees

On October 12, 2018, the US Department of Defense disclosed that a data breach at an unnamed commercial contractor had exposed travel records — including personal information and …

Supply chain [SC]

Central Banking / Central Bank of the Bahamas

2018-06-28 [vendor] Third-party website hosting provider (not disclosed)
Vector: Unauthorized access to external-facing public website via compromised third-party website hosting vendor

On June 28, 2018, the Central Bank of the Bahamas was made aware of unauthorized access to its external-facing public website. The bank's investigation confirmed that the breach …

Supply chain [SC]

Reddit / Krebs on Security / TechCrunch

2018-06-14 [vendor] SMS-based 2FA provider (not disclosed)
Vector: SMS-based two-factor authentication interception (SIM swap or SS7 exploitation) to compromise employee cloud and source code hosting accounts

On August 1, 2018, Reddit disclosed a security incident in which an attacker compromised several Reddit employee accounts at the company's cloud and source code hosting providers …

Supply chain [SC]

IT Pro / Enterprise Times / Silicon UK

2018-05-23 [vendor] PageUp [malware] Unspecified malware on PageUp systems
Vector: Malware infection of PageUp HR SaaS platform compromising authentication credentials and personal data

In June 2018, Whitbread plc -- the parent company of Costa Coffee, Premier Inn, Brewers Fayre, Beefeater, and other UK hospitality chains -- disclosed that personal data of job …

Supply chain

Houzz Data Breach — ~49 Million Users (2018–2019)

2018-05-23 [vendor] Houzz
Vector: Unauthorised access to Houzz user database; third-party attacker obtained user account data including hashed passwords

Houzz is a leading home design and renovation platform with tens of millions of registered users worldwide. In early 2019, the company disclosed that it had suffered a significant …

Supply chain [SC]

SC Media

2018-04-05 [vendor] Corporation Service Company (CSC)
Vector: Unauthorized network intrusion and data exfiltration from CSC systems

Corporation Service Company (CSC), a major provider of domain registration, corporate compliance, and agent-for-service-of-process services to Fortune 500 companies and other …

Supply chain [SC]

Bleeping Computer

2018-03-01 [vendor] Not disclosed [malware] POS RAM-scraping malware
Vector: Point-of-sale RAM-scraping malware deployed on restaurant POS systems

Brinker International, the parent company operating over 1,600 Chili's Grill and Bar restaurants worldwide, disclosed a payment card data breach on May 12, 2018, one day after …

Supply chain [SC]

NordVPN Finland Datacenter Server Breach

2018-03-01 [vendor] Unnamed Finland datacenter provider (remote management system)
Vector: Unauthorized access via undisclosed IPMI (Intelligent Platform Management Interface) remote management account installed by datacenter provider without NordVPN's knowledge

In October 2019, NordVPN disclosed that one of its rented servers at a datacenter in Finland had been accessed without authorization. The actual breach occurred in March 2018 — …

Supply chain [SC]

Ticketmaster UK Inbenta Magecart Supply Chain Attack — 40,000 Payment Cards

2018-02-01 [vendor] Inbenta Technologies chatbot (third-party vendor loaded on Ticketmaster payment pages) [malware] Magecart skimmer
Vector: Magecart Group 5 compromised Inbenta Technologies — a third-party AI-powered customer support chatbot provider — and injected malicious JavaScript into the Inbenta chat widget code; the malicious script was then automatically loaded onto Ticketmaster's payment pages, skimming payment card data in real-time

From approximately February to June 2018, Magecart Group 5 skimmed payment card data from Ticketmaster UK customers by compromising Inbenta Technologies — a third-party customer …

Supply chain [SC]

The Register

2018-01-01 [vendor] Not disclosed
Vector: Unauthorized access to external vendor system used for secure data storage

Western Union disclosed in early 2018 that customer information had been accessed without authorization through a computer intrusion targeting an external vendor system formerly …

Supply chain [SC]

PR Newswire / Latest Hacking News

2017-12-11 [vendor] SOCIAPlus [malware] JavaScript skimmer
Vector: Malicious JavaScript injection via compromised third-party analytics tool (SOCIAPlus)

Klook, a Hong Kong-based travel activities and services booking platform, disclosed on June 29, 2018 that it had suffered a data breach through a compromised third-party web …

Supply chain [SC]

HIPAA Journal

2017-12-01 [vendor] Undisclosed transcription service provider
Vector: Transcription vendor misconfigured database access during software upgrade

Orlando Orthopaedic Center reported a breach of 19,101 patient records caused by an error made by its third-party transcription service provider during a software upgrade in …

Supply chain [SC]

Threatpost

2017-11-23 [vendor] RMH Franchise Holdings [malware] POS RAM-scraping malware
Vector: Point-of-sale RAM-scraping malware deployed on POS systems at franchise locations

RMH Franchise Holdings, one of the largest Applebee's franchise operators in the United States, discovered malware on point-of-sale systems at its restaurants on February 13, 2018, …

Supply chain [SC]

Domino's Australia Customer Data Leak via Former Supplier

2017-10-01 [vendor] Unnamed former supplier (online rating system)
Vector: Compromise of former third-party supplier's online rating system

In October 2017, Domino's Australia customers began receiving targeted spam and phishing emails that addressed them by first name and referenced their local suburb, suggesting the …

Supply chain [SC]

StateScoop / Dark Reading / Gemini Advisory

2017-10-01 [vendor] Click2Gov (Superion / CentralSquare Technologies) [malware] SJavaWebManage web shell [cve] CVE-2017-3248 +2
Vector: Exploitation of Oracle WebLogic vulnerabilities (CVE-2017-3248, CVE-2017-3506, CVE-2017-10271) to upload web shell and enable payment card logging

Between late 2017 and late 2018, at least 46 US cities were compromised through vulnerabilities in Click2Gov, a self-service bill payment portal used by municipalities for utility …

Supply chain [SC]

CNN Business

2017-09-27 [vendor] [24]7.ai
Vector: Malicious code injection into [24]7.ai online customer service chat widget

Between September 27 and October 12, 2017, an unauthorized third party gained access to [24]7.ai's online customer service chat platform and injected malicious code designed to …

Supply chain [SC]

CCleaner Supply Chain Backdoor — 2.27 Million Users, Stage 2 Targets Samsung/Intel/Sony

2017-09-01 [vendor] Piriform CCleaner 5.33 (PC optimization utility, Windows) [malware] Floxif backdoor (Stage 1); Stage 2 GhostRat-variant (for high-value targets)
Vector: Chinese APT (BARIUM/Winnti Group) compromised Piriform's (later acquired by Avast) build environment and injected a two-stage backdoor into the legitimate CCleaner 5.33 Windows application; the trojanized software was digitally signed with Piriform's legitimate certificate and distributed through official download channels to millions of users

Between mid-August and 12 September 2017, Piriform (a subsidiary of Avast Security) distributed a backdoored version of CCleaner 5.33 — a widely used Windows PC cleaning utility — …

Supply chain [SC]

RiskIQ / Threatpost / ICO

2017-09-01 [vendor] Inbenta Technologies [malware] Magecart JavaScript card skimmer
Vector: Magecart JavaScript skimmer injected into Inbenta Technologies chatbot code running on Ticketmaster payment pages

In June 2018, Ticketmaster disclosed that malicious code had been found within a customer support chatbot function on its websites, hosted by third-party AI company Inbenta …

Supply chain [SC]

Huddle House POS Malware Breach via Third-Party Vendor (2017–2019)

2017-08-01 [vendor] Huddle House (POS vendor not publicly named) [malware] POS RAM scraper (card track data harvesting)
Vector: Attackers compromised a third-party POS vendor's support tools to gain remote access to Huddle House POS systems and deploy payment card scraping malware

Huddle House is a family-style restaurant chain headquartered in Atlanta, Georgia, with approximately 400 corporate and franchisee locations primarily across the southeastern …

Supply chain [SC]

NetSarang ShadowPad Supply Chain Backdoor — 100+ Corporate Victims

2017-07-01 [vendor] NetSarang Xmanager Enterprise / Xshell / Xftp (server management software) [malware] ShadowPad modular backdoor
Vector: Chinese APT (BRONZE ATLAS / Winnti Group) compromised NetSarang's software build infrastructure and inserted the ShadowPad modular backdoor into NetSarang's legitimate server management software products (Xmanager, Xshell, Xftp, Xlpd) before code signing; the signed trojanized software was distributed through NetSarang's official website

In July 2017, Kaspersky Lab researchers discovered that NetSarang Computer's server management software suite — used by hundreds of large enterprises globally for SSH, telnet, and …

Supply chain [SC]

Wikipedia

2017-06-27 [vendor] MeDoc (Intellect Service) [malware] NotPetya (Petya variant / wiper disguised as ransomware) [cve] CVE-2017-0144 +1
Vector: Compromised software update mechanism of MeDoc Ukrainian tax accounting software

On June 27, 2017, the NotPetya cyberattack struck, becoming one of the most destructive and costly cyberattacks in history with estimated global damages exceeding $10 billion. The …

Supply chain [SC]

NotPetya Supply Chain Wiper via M.E.Doc Update (Sandworm, $10B+ Damages)

2017-06-27 [vendor] M.E.Doc (MeDoc) Ukrainian tax accounting software [malware] NotPetya (Petya variant / wiper) [cve] CVE-2017-0144
Vector: Russian GRU Sandworm APT compromised M.E.Doc (MeDoc), a Ukrainian tax accounting software used by ~80% of Ukrainian companies, and trojanized the automatic update mechanism to deliver the NotPetya destructive wiper; lateral spread used EternalBlue + Mimikatz credential harvesting

On June 27, 2017, Russian military intelligence (GRU Unit 74455 / Sandworm) deployed NotPetya — a destructive wiper disguised as ransomware — by trojanizing the automatic update …

Supply chain [SC]

CSO Online

2017-05-13 [vendor] Apache Struts [cve] CVE-2017-5638
Vector: Exploitation of unpatched Apache Struts vulnerability (CVE-2017-5638) in web application portal

Between May 13 and July 30, 2017, attackers exploited a critical remote code execution vulnerability in Apache Struts (CVE-2017-5638) to breach Equifax, one of the three major US …

Supply chain [SC]

Handbrake macOS App Supply Chain Attack — Mac Users' Credentials Stolen

2017-05-01 [vendor] HandBrake video transcoder (mirror download server) [malware] Proton RAT (Remote Access Trojan) for macOS
Vector: Attackers compromised the HandBrake download mirror server and replaced the legitimate macOS HandBrake installer (HandBrake-1.0.7.dmg) with a trojanized version containing the Proton RAT; users who downloaded HandBrake from the compromised mirror between 2-6 May 2017 received malware instead of the legitimate application

Between 2-6 May 2017, attackers compromised one of HandBrake's macOS download mirror servers and replaced the legitimate HandBrake installer with a trojanized version containing …

Supply chain [SC]

Forever 21 Point-of-Sale Malware Breach

2017-04-03 [malware] POS RAM-scraping malware (unnamed)
Vector: Point-of-sale malware installed on in-store payment systems where encryption had been disabled

Between April 3 and November 18, 2017, point-of-sale malware infected payment systems at an undisclosed number of Forever 21 retail stores across the United States. The breach …

Supply chain [SC]

Hyatt Hotels Second Payment Card Breach (41 Properties)

2017-03-18 [malware] POS RAM-scraping malware (unnamed, dual-capability for swiped and manually entered cards)
Vector: Point-of-sale malware injected into front desk payment systems at managed hotel properties

Between March 18 and July 2, 2017, point-of-sale malware infected front desk payment systems at 41 Hyatt Hotels properties across 11 countries. The malware was capable of capturing …

Supply chain [SC]

Healthcare IT News

2016-12-22 [vendor] Unnamed patient management software vendor
Vector: Misconfiguration of third-party vendor patient management system

On December 22, 2016, an unauthorized individual gained access to electronic files stored on computer systems maintained by a third-party vendor that provided patient management …

Supply chain [SC]

HIPAA Journal

2016-08-28 [vendor] Managed service provider (unnamed)
Vector: Exposed RDP port opened by managed service provider to bypass VPN restrictions

Between August 28, 2016, and January 14, 2017, the Diamond Institute for Infertility and Menopause, a fertility clinic based in Millburn, New Jersey, suffered repeated unauthorized …

Data leak [SC]

Sabre Hospitality Solutions SynXis POS Breach — Hotel Reservations and Payment Cards

2016-08-10 [vendor] Sabre Hospitality Solutions SynXis Central Reservations system
Vector: Unauthorized actor gained access to Sabre Hospitality Solutions' SynXis Central Reservations (CR) system via compromised credentials of an authorised system user; once inside the SynXis CR system, the attacker accessed payment card data and personally identifiable information

Between 10 August 2016 and 9 March 2017, an unauthorized actor gained access to Sabre Corporation's SynXis Central Reservations (CR) hospitality technology system — a hotel …

Supply chain [SC]

Sabre SynXis Hospitality Reservation System Breach

2016-08-10 [vendor] Sabre Corp. (SynXis)
Vector: Unauthorized access to SynXis central reservation system using compromised account credentials

Between August 10, 2016, and March 9, 2017, an unauthorized party gained access to Sabre Corporation's SynXis central-reservations system, a widely used platform that processes …

Supply chain [SC]

Oracle MICROS POS System Breach — 330,000 Payment Terminals at Risk

2016-07-01 [vendor] Oracle MICROS customer support portal [malware] Carbanak malware
Vector: Carbanak/Anunak criminal group (Russian cybercriminal gang responsible for banking malware attacks) breached Oracle's MICROS customer support portal by installing malware on Oracle systems; the attacker gained access to the MICROS support portal used to service restaurant, hotel, and retail POS systems globally

In mid-2016, the Carbanak/Anunak cybercriminal gang — responsible for stealing over $1 billion from banks globally through sophisticated malware campaigns — breached Oracle's …

Supply chain [SC]

Newkirk Products Health Insurance ID Card Printer Breach — 3.4 Million Members

2016-05-11 [vendor] Newkirk Products ID card printing server
Vector: Unknown attacker gained unauthorized access to a server maintained by Newkirk Products — a company that prints and mails health insurance ID cards for multiple US health plans; the server contained personal information for health plan members across numerous client health insurers

On 11 May 2016, an unauthorized party gained access to a server maintained by Newkirk Products, Inc. — a company that prints and mails health insurance identification cards for …

Supply chain [SC]

Wendy's POS Malware Breach — 1,025 Restaurant Locations, Payment Cards

2015-10-01 [vendor] Wendy's restaurant POS systems (via third-party support vendor) [malware] Carbanak variant POS malware
Vector: Attackers compromised Wendy's third-party POS support vendor and used the vendor's remote access credentials to install memory-scraping malware (a variant of Carbanak/Anunak BlackPOS) on POS systems at Wendy's franchise locations; the malware captured Track 2 payment card data from device memory during transactions

Between October 2015 and mid-2016, a sophisticated POS malware attack — attributed to the Carbanak/Anunak criminal group — affected point-of-sale systems at 1,025 Wendy's franchise …

Supply chain [SC]

Experian / T-Mobile Data Breach — 15 Million T-Mobile Customer Applications

2015-09-01 [vendor] Experian Decision Analytics (T-Mobile credit check server)
Vector: An unknown attacker accessed Experian's server that stored personal information on behalf of T-Mobile; the server processed T-Mobile's credit application data and was accessed via a compromised credential that provided administrative access

In September 2015, Experian — a major US credit bureau — suffered a breach of a server it operated on behalf of T-Mobile for processing mobile phone service credit applications. …

Supply chain [SC]

T-Mobile/Experian Data Breach (CNBC, NPR, T-Mobile Newsroom)

2015-09-01 [vendor] Experian (credit check and decisioning services)
Vector: Unauthorized access to an Experian server containing T-Mobile credit application data; specific intrusion method not publicly disclosed

On October 1, 2015, Experian disclosed that hackers had gained unauthorized access to a server containing personal information of approximately 15 million people who had applied …

Supply chain [SC]

PNI Digital Media Photo Center Breach (Krebs on Security, NBC News, SC Magazine)

2015-06-01 [vendor] PNI Digital Media (online photo printing platform)
Vector: Malware installed on PNI Digital Media servers used to capture and exfiltrate customer payment card data and personal information from online photo center transactions

In June and July 2015, attackers compromised servers operated by PNI Digital Media, a Canadian company (subsidiary of Staples) that provided online photo printing and processing …

Data leak [SC]

Medical Informatics Engineering (MIE) / WebChart Breach — 3.9 Million Patients

2015-05-07 [vendor] Medical Informatics Engineering WebChart EHR (electronic health records)
Vector: An attacker used a compromised username and password to access Medical Informatics Engineering's cloud-based EHR system (WebChart) hosted server; the specific method of initial credential compromise was not disclosed but may have involved stolen credentials from other breaches or phishing

Between 7 and 26 May 2015, an attacker accessed Medical Informatics Engineering's (MIE) WebChart EHR cloud server using compromised credentials. MIE is a health information …

Supply chain [SC]

Marriott International / Starwood Data Breach (2018)

2014-07-29 [vendor] Starwood Hotels & Resorts Worldwide (acquired by Marriott in 2016) [malware] Remote Access Trojan (RAT); Mimikatz credential-harvesting tool; memory-scraping malware
Vector: Web shell planted on Starwood Accolade application server in July 2014 via compromised employee credentials (likely phishing), followed by RAT deployment for persistent access; credential harvesting with Mimikatz; lateral movement through Starwood guest reservation database (SPG) over four years before detection in September 2018

The Marriott/Starwood breach is one of the largest data breaches in history and a landmark case study in the risks of inheriting a compromised IT environment through corporate …

Supply chain [SC]

Lowe's Driver Records Breach via SafetyFirst E-Driver File Platform

2014-07-01 [vendor] SafetyFirst E-Driver File (driver management platform)
Vector: SafetyFirst's E-Driver File online database system — used by Lowe's to store driver qualification records for commercial vehicle operators — had a configuration error or vulnerability that exposed driver records to unauthorized access

In a letter to both current and former employees, Lowe’s says that personal information might have been compromised after a third-party vendor exposed it to the public. In a letter …

Supply chain [SC]

JPMorgan Chase 2014 Data Breach (WSJ, NYT, SEC filings)

2014-06-01 [vendor] JPMorgan Chase corporate network and web applications
Vector: Stolen employee credentials from a compromised personal computer; attackers exploited a vulnerability in a web application server and escalated access due to a missing two-factor authentication token on one network server

In June 2014, attackers compromised a JPMorgan Chase employee's personal computer and obtained login credentials, which they used to gain initial access to the bank's corporate …

Supply chain [SC]

Boston Medical Center Patient Records Breach via MDF Transcription Services

2014-04-01 [vendor] MDF Transcription Services
Vector: MDF Transcription Services, a medical transcription vendor contracted by Boston Medical Center, inadvertently posted patient records to a publicly accessible website without authentication; the records were uploaded to an internet-accessible server rather than a secure private system

Boston Medical Center said it has fired a transcription service after a health care provider reported that the medical records of about 15,000 patients at the hospital were posted …

Supply chain [SC]

NBC News

2014-01-01 [vendor] iHealth Innovations
Vector: Misconfigured rsync backup server left publicly accessible without authentication

On May 3, 2017, security researcher Bob Diachenko of the Kromtech Security Research Center discovered a massive trove of patient records from Bronx-Lebanon Hospital Center in New …

Supply chain [SC]

Mercedes-Benz USA Cloud Vendor Breach — 1.6M Records Exposed, SSNs and Credit Card Data for ~1,000

2014-01-01 [vendor] Unnamed cloud storage vendor (Mercedes-Benz USA)
Vector: Misconfigured cloud storage platform — an unnamed vendor left a dataset of Mercedes-Benz customer records unsecured and accessible via the internet

Mercedes-Benz USA (MBUSA) disclosed on June 11, 2021, that a vendor had inadvertently left sensitive customer and prospective buyer data accessible on a cloud storage platform. The …

Supply chain [SC]

Target Corporation BlackPOS POS Malware Breach via Fazio Mechanical HVAC Vendor

2013-11-01 [vendor] Fazio Mechanical Services (HVAC contractor) / Target vendor portal [malware] BlackPOS (Kaptoxa) RAM-scraping malware; Citadel malware (on vendor's systems)
Vector: Attackers stole network credentials from Fazio Mechanical Services — a Pennsylvania HVAC (heating, ventilation, and air conditioning) contractor — by infecting Fazio employee computers with Citadel malware; these credentials provided access to Target's vendor portal, from which attackers pivoted to Target's POS network and installed BlackPOS RAM-scraping malware

Last week, Target told reporters at The Wall Street Journal and Reuters that the initial intrusion into its systems was traced back to network credentials that were stolen from a …

Supply chain [SC]

Florida Healthy Kids Corporation (FHKC) / Jelly Bean Communications Design breach

2013-11-01 [vendor] Jelly Bean Communications Design (web hosting vendor for FHKC enrollment portal)
Vector: Unpatched web application vulnerabilities at third-party hosting vendor exploited over seven years; vendor failed to apply CMS/PHP security patches from November 2013 through December 2020

Florida Healthy Kids Corporation (FHKC) administers the Florida KidCare health insurance program, providing subsidized health and dental coverage to children across Florida. FHKC …

Supply chain [SC]

SEC Administrative Proceeding against R.T. Jones Capital Equities Management

2013-07-22 [vendor] Artesys (third-party web server hosting)
Vector: Compromise of third-party-hosted web server (Artesys platform); attackers gained access and copy rights to PII stored on the server

On July 22, 2013, R.T. Jones Capital Equities Management, a St. Louis-based registered investment adviser, discovered that its third-party-hosted web server had been compromised by …

Supply chain [SC]

Goodwill Industries POS Malware Breach — Payment Card Data at Thrift Stores

2013-02-01 [vendor] C&K Systems (third-party POS service provider for Goodwill Industries) [malware] POS RAM-scraping malware
Vector: Malware was installed on point-of-sale systems at Goodwill Industries stores nationwide through a compromised third-party payment processing vendor (C&K Systems); the malware collected payment card track data during transactions

Beginning in February 2013, a third-party point-of-sale service provider to Goodwill Industries — C&K Systems, a payment processing vendor — had its systems compromised with …